3.6.3.3 FTPD: Disable root access to ftp

Information

This change adds the root user to the /etc/ftpusers file, which disables ftp for root.

Rationale:

This change ensures that direct root ftp access is disabled. As detailed previously, ftp as a service should be disabled. If the service has to be enabled then this change must be implemented to ensure that remote root file transfer access is not enabled.

Solution

Add root to the /etc/ftpusers file:

echo 'root' >> /etc/ftpusers

Default Value:

N/A

See Also

https://workbench.cisecurity.org/files/4119

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6(2), 800-53|AC-6(5), CSCv7|4.3

Plugin: Unix

Control ID: 95c69d55bb49f8906ff0f06f7cd713b21b13ea3a0453487189c0fe671879b779