UCF STIG Viewer Logo

The ALG must generate error messages providing information necessary for corrective actions without revealing organizationally defined sensitive or potentially harmful information in error logs and administrative messages that could be exploited.


Overview

Finding ID Version Rule ID IA Controls Severity
SRG-NET-000273-ALG-000129 SRG-NET-000273-ALG-000129 SRG-NET-000273-ALG-000129_rule Medium
Description
Any network element providing too much information in error messages risks compromising the data and security of the application and system. The structure and content of error messages need to be carefully considered by the organization and development team. Organizations carefully consider the structure/content of error messages. The extent to which information systems are able to identify and handle error conditions is guided by organizational policy and operational requirements. Information that could be exploited by adversaries includes, for example, ICMP messages that reveal the use of firewalls or access-control lists. This requirement applies to gateways and firewalls that perform content inspection or have higher-layer proxy functionality.
STIG Date
Application Layer Gateway Security Requirements Guide 2014-06-27

Details

Check Text ( C-SRG-NET-000273-ALG-000129_chk )
Verify the ALG reveals error messages only to the IAO, IAM, and SA.

If the ALG does not reveal error messages only to the IAO, IAM, and SA, this is a finding.
Fix Text (F-SRG-NET-000273-ALG-000129_fix)
Configure the ALG to reveal error messages only to the IAO, IAM, and SA.