GEN004920 - The ftpusers file must be owned by root - '/etc/vsftpd.ftpusers'

Information

If the file ftpusers is not owned by root, an unauthorized user may modify the file to allow unauthorized accounts to use FTP.

Solution

Change the owner of the ftpusers file to root.
For gssftp:
# chown root /etc/ftpusers

For vsftp:
# chown root /etc/vsftpd.ftpusers /etc/vsftpd/ftpusers

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-6, 800-53|SC-4, CAT|II, CCI|CCI-000225, CCI|CCI-001090, Rule-ID|SV-218559r603259_rule, STIG-ID|GEN004920, STIG-Legacy|SV-63009, STIG-Legacy|V-842, Vuln-ID|V-218559

Plugin: Unix

Control ID: 657a5539bd665a47e6ef4fe30a518ec34d4907f7d4a53ebdc80081b9ca8535cc