Ensure Default HTML Content Is Removed
Scanned 5/30/2026
Install via CLI
openskills install CyberStrikeus/CyberStrike---
name: cis-apache-5.4
description: "Ensure Default HTML Content Is Removed"
category: cis-apache
version: "3.6.0"
author: cyberstrike-official
tags: [cis, apache, linux, features, content, options]
cis_id: "5.4"
cis_benchmark: "CIS Apache HTTP Server 2.2 Benchmark v3.6.0"
tech_stack: [linux, apache]
cwe_ids: []
chains_with: []
prerequisites: []
severity_boost: {}
---
# Ensure Default HTML Content Is Removed
## Description
Apache installations have default content that is not needed or appropriate for production use. The primary function for the sample content is to provide a default web site, provide user manuals, or demonstrate special features of the web server. All content that is not needed should be removed.
## Rationale
Historically, sample content and features have been remotely exploited and can provide different levels of access to the server. Usually these routines are not written for production use and consequently little thought was given to security in their development.
## Impact
None documented
## Audit Procedure
Perform the following to determine if the recommended state is implemented:
1. Verify the document root directory and the configuration files do not provide for a default index.html or welcome page.
2. Ensure the Apache User Manual content is not installed by checking the configuration files for manual location directives.
3. Verify the Apache configuration files do not have the Server Status handler configured.
4. Verify that the Server Information handler is not configured.
5. Verify that any other handler configurations such as `perl-status` are not enabled.
## Remediation
Review all pre-installed content and remove content which is not required. In particular, look for unnecessary content in the document root directory, in a configuration directory such as `conf/extra` directory, or as a Unix/Linux package.
1. Remove the default `index.html` or welcome page if it is a separate package. If the default welcome page is part of the main Apache `httpd` package, such as it is on Red Hat Linux, then comment out the configuration as shown below. Removing a file such as the `welcome.conf` is not recommended as it may get replaced if the package is updated.
```apache
#
# This configuration file enables the default "Welcome"
# page if there is no default index page present for
# the root URL. To disable the Welcome page, comment
# out all the lines below.
#
##<LocationMatch "^/+$">
## Options -Indexes
## ErrorDocument 403 /error/noindex.html
##</LocationMatch>
```
2. Remove the Apache user manual content or comment out configurations referencing the manual.
```bash
# yum erase httpd-manual
```
3. Remove or comment out any Server Status handler configuration.
```apache
#
# Allow server status reports generated by mod_status,
# with the URL of http://servername/server-status
# Change the ".example.com" to match your domain to enable.
#
##<Location /server-status>
## SetHandler server-status
## Order deny,allow
## Deny from all
## Allow from .example.com
##</Location>
```
4. Remove or comment out any Server Information handler configuration.
```apache
#
# Allow remote server configuration reports, with the URL of
# http://servername/server-info (requires that mod_info.c be loaded).
# Change the ".example.com" to match your domain to enable.
#
##<Location /server-info>
## SetHandler server-info
## Order deny,allow
## Deny from all
## Allow from .example.com
##</Location>
```
5. Remove or comment out any other handler configurations such as `perl-status`.
```apache
# This will allow remote server configuration reports, with the URL of
# http://servername/perl-status
# Change the ".example.com" to match your domain to enable.
##<Location /perl-status>
## SetHandler perl-script
## PerlResponseHandler Apache2::Status
## Order deny,allow
## Deny from all
## Allow from .example.com
##</Location>
```
## Default Value
The default source build extra content is available in the
/usr/local/apache2/conf/extra/ directory, but the configuration of the extra content is commented out by default. The only default content is a minimal barebones index.html in the document root which contains the following:
```html
<html>
<body>
<h1>It works!</h1>
</body>
</html>
```
## References
None documented
## CIS Controls
Version 6
18.9 Sanitize Deployed Software Of Development Artifacts
For in-house developed applications, ensure that development artifacts (sample data and scripts; unused libraries, components, debug code; or tools) are not included in the deployed software, or accessible in the production environment.
Version 7
5.1 Establish Secure Configurations
Maintain documented, standard security configuration standards for all authorized operating systems and software.
## Profile
Level 1 | Scored
No comments yet. Be the first to comment!