Web Server audit fixes
Configuration Hardening: fixing all 6 checks
Configuration hardening inspects the permissions on your config files, private keys and document roots, and the caps on request size, timeouts and rate that keep one client from exhausting the server.
The two permission checks skip on missing evidence rather than missing privilege: config permissions skips when neither /etc/nginx nor an Apache config root exists, and web root ownership skips when the config the audit could read carried no root or DocumentRoot line. Risky Apache Modules skips on every nginx-only host by design, and again when Apache is installed but no module list could be built.
Transcribed from the web-server-security-configuration-hardening audit script.
Find your finding
Listed in the order the audit runs them. Take the check name from the third field of the result line and open its page.
Web Server Config Permissions
SoonChecks the web server config directory for world-writable config files and world-readable private keys
HighNeeds root3 resultsWeb Root Ownership
SoonChecks whether document roots are world-writable or owned by the web server worker user
HighNeeds root4 resultsRequest Size Limits
SoonChecks whether a request body size cap is set via client_max_body_size or LimitRequestBody
MediumNo root3 resultsConnection Timeouts
SoonChecks whether request timeouts are configured to blunt slow-request attacks
LowNo root3 resultsRate Limiting
SoonChecks whether rate or connection limiting is configured for login and API paths
MediumNo root3 resultsRisky Apache Modules
SoonChecks the enabled Apache module list for optional modules that widen the attack surface
LowNo root3 results
How the Configuration Hardening audit reads your server
Every check in this audit runs after the same preamble, and several of its results only make sense once you know what that preamble could and could not see.
All web-server scripts share one preamble. It detects nginx, Apache (apache2/httpd, APROOT = /etc/apache2 or /etc/httpd), Caddy and lighttpd. NGT is nginx -T output (effective config with every include expanded) when root, otherwise a concatenation of nginx.conf, conf.d/*.conf, sites-enabled/*. APC is the concatenated Apache config tree (main file, ports.conf, conf.d, conf-enabled, sites-enabled, mods-enabled, conf.modules.d), comments stripped; APM is apachectl -M (root) or the mods-enabled/*.load names. WROOTS are all root/DocumentRoot values. A live probe curls https://127.0.0.1/, http://127.0.0.1/, http://127.0.0.1:8080/ with the first real server_name/ServerName as Host:. hdr NAME reads a response header; code URL returns the HTTP status. Caddy and lighttpd are detected but their configs are not parsed, so most checks on those hosts rely on the live probe only. Messages ending in "(no live response, config only)" or "(default vhost only - no server_name found to probe)" mean the probe could not be used.
A SKIP is never a pass
A skipped check verified nothing at all. The most common cause is privilege: 2 of the 6 checks in this audit need root for a complete result. Before every run, each script works out which of four privilege modes it is in.
| Mode | How it is reached | What it means for your results |
|---|---|---|
root | The audit runs as UID 0. | Every privileged branch runs directly. No check skips for lack of permission. |
nopass | sudo -n true succeeds, so the account has passwordless sudo. | Privileged commands run through sudo -n. |
pass | A sudo password was supplied in the CtrlOps audit settings and accepted. | Privileged commands run through sudo -S. |
none | None of the above worked. | CAN_ROOT=0. Every privileged branch returns SKIP with a "Need root" message rather than guessing. |
If many checks skip with a “need root” message, run the audit as root, grant the audit account sudo (with or without NOPASSWD), or supply the sudo password in the CtrlOps audit settings.
Configuration Hardening questions
Run all 6 Configuration Hardening checks, in one click
CtrlOps runs this audit over your existing SSH connection - no agents, no scripts to manage. $7/user/month after a 1 month free trial - no credit card required.
✓ Start instantly·✓ No credit card·✓ No sneaky autorenewals