ALMA-09-037750 - AlmaLinux OS 9 must not have any File Transfer Protocol (FTP) packages installed.

Information

Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised.

An FTP server provides an unencrypted file transfer mechanism that does not protect the confidentiality of user credentials or the remote session.

If a privileged user were to log on using this service, the privileged user password could be compromised. SFTP or other encrypted file transfer methods must be used instead.

Removing the server and client packages prevents inbound and outbound communications from being compromised.

Solution

Remove the default FTP client and server packages using the following command:

$ dnf remove vsftpd ftp

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_CL_AlmaLinux_OS_9_V1R1_STIG.zip

Item Details

Category: IDENTIFICATION AND AUTHENTICATION

References: 800-53|IA-5(1)(c), CAT|I, CCI|CCI-000197, Rule-ID|SV-269403r1050286_rule, STIG-ID|ALMA-09-037750, Vuln-ID|V-269403

Plugin: Unix

Control ID: f81eeb8822e4ae85504a5c9b57817f9da0ca1f232848deb17248da8d62630de8