GEN004900 - The ftpusers file must contain account names not allowed to use FTP.

Information

The ftpusers file contains a list of accounts not allowed to use FTP to transfer files. If the file does not contain the names of all accounts not authorized to use FTP, then unauthorized use of FTP may take place.

Solution

For gssftp:
Add accounts not allowed to use FTP to the /etc/ftpusers file.

For vsftp:
Add accounts not allowed to use FTP to the /etc/vsftpd.ftpusers or /etc/vsftpd/ftpusers file (as appropriate).

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-6, 800-53|SC-4, CAT|II, CCI|CCI-000225, CCI|CCI-001090, Rule-ID|SV-218558r603259_rule, STIG-ID|GEN004900, STIG-Legacy|SV-62981, STIG-Legacy|V-841, Vuln-ID|V-218558

Plugin: Unix

Control ID: bce3ddac4116e4622cab861edb51b1bfda0b196e0ccdb529e512ec9fd5bb1737