Web Server audit fixes
Content Exposure: fixing all 6 checks
The content exposure audit requests paths from the running server and searches the document roots for what you never meant to publish: directory listings, .git and .env, backups and status endpoints.
Only two things cause a skip here: no web server detected at all, and, for Exposed Backup Files, no root or DocumentRoot line in the config the audit could read. Every other check still returns a verdict when the loopback probe got no response, so on an unreachable host several of the PASSes rest on config text alone.
Transcribed from the web-server-security-content-exposure audit script.
Find your finding
Listed in the order the audit runs them. Take the check name from the third field of the result line and open its page.
Directory Listing
SoonChecks whether directory listing is enabled in the config and whether the server actually serves one
MediumNo root4 resultsHidden File Exposure
SoonProbes whether dotfiles such as .git and .env in the web root are reachable over HTTP
HighNeeds root4 resultsExposed Backup Files
SoonChecks the document roots for backup, editor and archive files that visitors could download
MediumNeeds root4 resultsDangerous HTTP Methods
SoonProbes whether TRACE is answered and whether the Allow header advertises write methods
MediumNo root4 resultsExposed Status Endpoints
SoonChecks whether server status and info endpoints are reachable without an access restriction
MediumNo root3 resultsDefault Welcome Pages
SoonChecks whether the stock welcome page or the distribution default vhost is still being served
LowNo root3 results
How the Content Exposure audit reads your server
Every check in this audit runs after the same preamble, and several of its results only make sense once you know what that preamble could and could not see.
.
All web-server scripts share one preamble. It detects nginx, Apache (apache2/httpd, APROOT = /etc/apache2 or /etc/httpd), Caddy and lighttpd. NGT is nginx -T output (effective config with every include expanded) when root, otherwise a concatenation of nginx.conf, conf.d/*.conf, sites-enabled/*. APC is the concatenated Apache config tree (main file, ports.conf, conf.d, conf-enabled, sites-enabled, mods-enabled, conf.modules.d), comments stripped; APM is apachectl -M (root) or the mods-enabled/*.load names. WROOTS are all root/DocumentRoot values. A live probe curls https://127.0.0.1/, http://127.0.0.1/, http://127.0.0.1:8080/ with the first real server_name/ServerName as Host:. hdr NAME reads a response header; code URL returns the HTTP status. Caddy and lighttpd are detected but their configs are not parsed, so most checks on those hosts rely on the live probe only. Messages ending in "(no live response, config only)" or "(default vhost only - no server_name found to probe)" mean the probe could not be used.
A SKIP is never a pass
A skipped check verified nothing at all. The most common cause is privilege: 2 of the 6 checks in this audit need root for a complete result. Before every run, each script works out which of four privilege modes it is in.
| Mode | How it is reached | What it means for your results |
|---|---|---|
root | The audit runs as UID 0. | Every privileged branch runs directly. No check skips for lack of permission. |
nopass | sudo -n true succeeds, so the account has passwordless sudo. | Privileged commands run through sudo -n. |
pass | A sudo password was supplied in the CtrlOps audit settings and accepted. | Privileged commands run through sudo -S. |
none | None of the above worked. | CAN_ROOT=0. Every privileged branch returns SKIP with a "Need root" message rather than guessing. |
If many checks skip with a “need root” message, run the audit as root, grant the audit account sudo (with or without NOPASSWD), or supply the sudo password in the CtrlOps audit settings.
Content Exposure questions
Run all 6 Content Exposure checks, in one click
CtrlOps runs this audit over your existing SSH connection - no agents, no scripts to manage. $7/user/month after a 1 month free trial - no credit card required.
✓ Start instantly·✓ No credit card·✓ No sneaky autorenewals