Rule ID
SV-256735r888796_rule
Version
V1R2
CCIs
CCI-002385
An attacker has at least two reasons to stop a web server. The first is to cause a denial of service, and the second is to put in place changes the attacker made to the web server configuration. If the Tomcat shutdown port feature is enabled, a shutdown signal can be sent to the Lookup Service through this port. To ensure availability, the shutdown port must be disabled.
At the command prompt, run the following commands:
# xmllint --xpath '/Server/@port' /usr/lib/vmware-lookupsvc/conf/server.xml
Expected result:
port="${base.shutdown.port}"
If the output does not match the expected result, this is a finding.Navigate to and open:
/usr/lib/vmware-lookupsvc/conf/server.xml
Ensure the server port is set as follows:
<Server port="${base.shutdown.port}">
Restart the service with the following command:
# vmon-cli --restart lookupsvc