Hub rules-apache

rules-apache

v5 public Verified

Apache

The Apache HTTP Server is a widely-used web server software. These rules govern configuration best practices, security hardening, and module management for AI-assisted Apache server administration.

@sigmashakeinc 2 pulls 8 rules published Apr 8, 2026 synced Oct 4, 2026 sigmashakeinc/rules/rulesets/rules-apache →
Severity
6 error 2 warn 0 info
demo.cast
The Apache HTTP Server is a widely-used web server software. These rules govern configuration best practices, security hardening, and module management for AI-assisted Apache server administration.

Rules index

8 governance rules

Indexed from the repository's .rules files, grouped by technology. Expand any rule to read the raw source.

apache

apache-allow-override-all warning log

RISK: 'AllowOverride All' lets any .htaccess file in the document root override security directives — a single writable directory lets an attacker re-enable directory listings, add PHP handlers, or bypass authentication. FIX: set 'AllowOverride None' at the root and grant only the specific override categories needed (e.g., 'AllowOverride AuthConfig') for directories that require it.

Rule source requires an active Pro or Enterprise subscription.
apache-directory-listing error block

Enabling 'Indexes' allows directory listing, exposing your file structure and sensitive files to the public. Use 'Options -Indexes' to disable this.

Rule source requires an active Pro or Enterprise subscription.
apache-htpasswd-in-webroot error block

RISK: writing a .htpasswd file inside the web document root makes it retrievable via HTTP GET if .htaccess protection is misconfigured or absent. Even with MD5-hashed credentials, offline cracking is trivial. FIX: store .htpasswd above the DocumentRoot (e.g., /etc/apache2/.htpasswd) and reference it with an absolute path in the AuthUserFile directive.

Rule source requires an active Pro or Enterprise subscription.
apache-mod-status-public error block

RISK: mod_status/mod_info handler without 'Require local' exposes detailed server internals (worker state, request URLs, client IPs, uptime, module list) to any internet client — reconnaissance goldmine for attackers. FIX: restrict with 'Require local' or a named IP allowlist inside the <Location /server-status> block, or remove the handler entirely in production.

Rule source requires an active Pro or Enterprise subscription.
apache-root-directory-access error block

The root directory (<Directory />) must be locked down by default to prevent access to the entire server file system. Ensure 'Require all denied' is set.

Rule source requires an active Pro or Enterprise subscription.
apache-server-tokens warning log

Apache reveals its version and OS information by default. Attackers use this for reconnaissance. Add 'ServerTokens Prod' to hide version details.

Rule source requires an active Pro or Enterprise subscription.
apache-trace-method-enabled error block

RISK: TraceEnable On enables the HTTP TRACE method, which is exploitable via Cross-Site Tracing (XST — OWASP A05) to steal session cookies even when HttpOnly is set, because TRACE echoes all request headers including cookies. FIX: add 'TraceEnable Off' to the global server config or every VirtualHost block. Most modern Apache installs default to Off, but explicit config prevents it being re-enabled by accident.

Rule source requires an active Pro or Enterprise subscription.
apache-weak-ssl-protocols error block

Enabling weak or deprecated SSL/TLS protocols (SSLv2, SSLv3, TLS 1.0, TLS 1.1) exposes the server to cryptographic downgrade attacks. Allow only TLSv1.2 and TLSv1.3.

Rule source requires an active Pro or Enterprise subscription.

Version metadata

Published metadata

The hash-locked record of this published ruleset. When source contents change, the maintainer resyncs and the version bumps.

Version
v5
Published
Apr 8, 2026
Source commits
0
Synced
Oct 4, 2026
Hash
3e75658d7d451796aa8ed35d69c0e8f62a40287033dea3a979dadbb82380900c
Signature
Verified (publisher key)
Tested with
claude-code@current
Plan
Starter (free)
Visibility
Public

Source history

Recent commits

Latest commits touching rulesets/rules-apache/.sigmashake/rules in sigmashakeinc/rules/rulesets/rules-apache. The published version only bumps when a maintainer resyncs.

No commit history available.