GEN004820 - Anonymous FTP must not be active on the system unless authorized - 'ftp'

Information

Due to the numerous vulnerabilities inherent in anonymous FTP, it is not recommended for use. If anonymous FTP must be used on a system, the requirement must be authorized and approved in the system accreditation package.

Solution

Configure the FTP service to not permit anonymous logins. Remove the user(s) ftp and/or anonymous from the /etc/passwd file.

See Also

https://iasecontent.disa.mil/stigs/zip/U_HPUX_11-31_V1R19_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3, CAT|II, CCI|CCI-001475, Rule-ID|SV-35100r1_rule, STIG-ID|GEN004820, Vuln-ID|V-846

Plugin: Unix

Control ID: c5bb10e97cd6a341c0a2418fc83669398c89a0111c9ad515a7f9384583ad589b