GEN004900 - The ftpusers file must contain account names not allowed to use FTP.

Information

The ftpusers file contains a list of accounts not allowed to use FTP to transfer files. If the file does not contain the names of all accounts not authorized to use FTP, then unauthorized use of FTP may take place.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

For gssftp:
Add accounts not allowed to use FTP to the /etc/ftpusers file.

For vsftp:
Add accounts not allowed to use FTP to the /etc/vsftpd.ftpusers or /etc/vsftpd/ftpusers file (as appropriate).

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-6, CAT|II, CCI|CCI-000225, Group-ID|V-841, Rule-ID|SV-52091r1_rule, STIG-ID|GEN004900, Vuln-ID|V-841

Plugin: Unix

Control ID: 9a0291b82595ddb405090521e86a3811eb95730a194e2051b76c98bbe470a91a