GEN004880 - The ftpusers file must exist.

Information

The ftpusers file contains a list of accounts not allowed to use FTP to transfer files. If this file does not exist, then unauthorized accounts can utilize FTP.

Solution

Create an ftpusers file appropriate for the running FTP service.
For gssftp:
Create an /etc/ftpusers file containing a list of accounts not authorized for FTP.

For vsftp:
Create an /etc/vsftpd.ftpusers or /etc/vsftpd/ftpusers (as appropriate) file containing a list of accounts not authorized for FTP.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-840, Rule-ID|SV-51983r1_rule, STIG-ID|GEN004880, Vuln-ID|V-840

Plugin: Unix

Control ID: f3a9a1fe4f68837521643dffef893928b367c8bf0ac40afe7d51a91afc1b5e07