BSI-100-2: S 4.21: Preventing unauthorised acquisition of administrator rights: Block ftp for administrative accesses.

Warning! Audit Deprecated

This audit has been deprecated and will be removed in a future update.

View Next Audit Version


The file /etc/ftpusers contains the log-in names which are not allowed to log on via ftp. With ftp, passwords are transmitted over an unprotected plain text connection. Therefore, administrative accesses (root, bin, daemon, sys, adm, lp, smtp, uucp, nuucp, etc.) should be entered in this file. Under some standard installations, root is not contained in this file.

Safeguard Catalogues: S 4: Hardware and software

S 4.21: Preventing unauthorised acquisition of administrator rights

See Also

Item Details


References: 800-53|AC-6(2)

Plugin: Unix

Control ID: fcc8a558c66207bfe750be7134c8c040f180d8669e42b5a388420aa9fc573c30