GEN004820 - Anonymous FTP must not be active on the system unless authorized.

Information

Due to the numerous vulnerabilities inherent in anonymous FTP, it is not recommended. If anonymous FTP must be used on a system, the requirement must be authorized and approved in the system accreditation package.
NOTE: Nessus has not performed this query, and this check is only provided for informational purposes.

Solution

Configure the FTP service to not permit anonymous logins.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R17_STIG.zip

Item Details

References: CAT|II, CCI|CCI-001475, Group-ID|V-846, Rule-ID|SV-37526r1_rule, STIG-ID|GEN004820

Plugin: Unix

Control ID: f45bb2cd624d6e1320788e8968d5158e06f9a47e635d9324b46d22a413fd4773