Alter the Advertised server.built Date (Scored)
Skills in this repository
CyberStrikeus/CyberStrike - Page 34
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Disable X-Powered-By HTTP Header and Rename the Server Value for all Connectors (Scored)
Disable client facing Stack Traces (Scored)
Turn off TRACE (Scored)
Ensure Sever Header is Modified To Prevent Information Disclosure (Not Scored)
Set a nondeterministic Shutdown command value (Scored)
Disable the Shutdown port (Not Scored)
Restrict access to $CATALINA_HOME (Scored)
Restrict access to $CATALINA_BASE (Scored)
Restrict access to Tomcat configuration directory (Scored)
Restrict access to Tomcat logs directory (Scored)
Restrict access to Tomcat temp directory (Scored)
Restrict access to Tomcat binaries directory (Scored)
Restrict access to Tomcat web application directory (Scored)
Restrict access to Tomcat catalina.properties (Scored)
Restrict access to Tomcat catalina.policy (Scored)
Control the maximum size of a POST request that will be parsed for parameters (Scored)
Application specific logging (Automated)
Specify file handler in logging.properties files (Automated)
Ensure className is set correctly in context.xml (Automated)
Ensure directory in context.xml is a secure location (Manual)
Ensure pattern in context.xml is correct (Automated)
Ensure directory in logging.properties is a secure location (Automated)
Restrict runtime access to sensitive packages (Automated)
Disabling auto deployment of applications (Automated)
Disable deploy on startup of applications (Automated)
Disable deploy on startup of applications (Scored)
Remove extraneous files and directories (Manual)
Disable Unused Connectors (Manual)
Ensure Web content directory is on a separate partition from the Tomcat system files (Manual)
Configure maxHttpHeaderSize (Automated)
Force SSL for all applications (Automated)
Do not allow symbolic linking (Automated)
Do not run applications as privileged (Automated)
Do not allow cross context requests (Automated)
Do not resolve hosts on logging valves (Automated)
Enable memory leak listener (Automated)
Setting Security Lifecycle Listener (Automated)
Use the logEffectiveWebXml and metadata-complete settings for deploying applications in production (Automated)
Ensure Manager Application Passwords are Encrypted (Manual)