Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
SRG-NET-000273-ALG-000129 | SRG-NET-000273-ALG-000129 | SRG-NET-000273-ALG-000129_rule | Medium |
Description |
---|
Any network element providing too much information in error messages risks compromising the data and security of the application and system. The structure and content of error messages need to be carefully considered by the organization and development team. Organizations carefully consider the structure/content of error messages. The extent to which information systems are able to identify and handle error conditions is guided by organizational policy and operational requirements. Information that could be exploited by adversaries includes, for example, ICMP messages that reveal the use of firewalls or access-control lists. This requirement applies to gateways and firewalls that perform content inspection or have higher-layer proxy functionality. |
STIG | Date |
---|---|
Application Layer Gateway Security Requirements Guide | 2014-06-27 |
Check Text ( C-SRG-NET-000273-ALG-000129_chk ) |
---|
Verify the ALG reveals error messages only to the IAO, IAM, and SA. If the ALG does not reveal error messages only to the IAO, IAM, and SA, this is a finding. |
Fix Text (F-SRG-NET-000273-ALG-000129_fix) |
---|
Configure the ALG to reveal error messages only to the IAO, IAM, and SA. |