Skip to content

Disable Autoindex Module #10

Description

@JJediny

Draft CIS Benchmark 1.1.11

Description

The nginx processes requests ending with the slash character (‘/’) and produces a directory listing. Usually a request is passed to the ngx\_http\_autoindex\_module module when the ngx\_http\_index\_module module cannot find an index file.

Rationale

Automated directory listings should not be enabled as it will also reveal information helpful to an attacker such as naming conventions and directory paths. Directory listings may also reveal files that were not intended to be revealed.

Remediation

Perform the following to implement the recommended state: 1. Search the NGINX configuration files (nginx.conf and any included configuration files) to find autoindex directives. grep -i '^\s*autoindex\s+' $NGINX_PREFIX/nginx.conf grep -i '^\s*autoindex\s+' $NGINX_PREFIX/conf.d/* 2. Set the value for all autoindex directives to off or remove those directives.

Audit

Perform the following to determine if the recommended state is implemented: 1. Search the NGINX configuration files (nginx.conf and any included configuration files) to find any autoindex directives: grep -i '^\s*autoindex\s+' $NGINX_PREFIX/nginx.conf grep -i '^\s*autoindex\s+' $NGINX_PREFIX/conf.d/* 2. Ensure there are no autoindex directives present or they values are set to off for each founded directive.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions