4.7.2.1 Ensure root access to ftpd is disabled

Information

This change adds the root user to the /etc/ftpusers file, which disables ftp for root.

This change ensures that direct root ftp access is disabled. As detailed previously, ftp as a service should be disabled. If the service has to be enabled then this change must be implemented to ensure that remote root file transfer access is not enabled.

Solution

Add root to the /etc/ftpusers file:

echo "root" >> /etc/ftpusers

See Also

https://workbench.cisecurity.org/benchmarks/10385

Item Details

Category: ACCESS CONTROL, MEDIA PROTECTION

References: 800-53|AC-3, 800-53|AC-5, 800-53|AC-6, 800-53|MP-2, CSCv7|14.6

Plugin: Unix

Control ID: 89c459d92fde597eeb26963f0cf0c87a5d25cd01ee150820a2c543333b1d9209