GEN004820 - Anonymous FTP must not be active on the system unless authorized.

Information

Due to the numerous vulnerabilities inherent in anonymous FTP, it is not recommended. If anonymous FTP must be used on a system, the requirement must be authorized and approved in the system accreditation package.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Configure the FTP service to not permit anonymous logins.

See Also

http://iasecontent.disa.mil/stigs/zip/U_RedHat_5_V1R18_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-22c., CAT|II, CCI|CCI-001475, Group-ID|V-846, Rule-ID|SV-37526r1_rule, STIG-ID|GEN004820, Vuln-ID|V-846

Plugin: Unix

Control ID: fb020ddc74837e070726445ed65e8a5c8b081a2d717d5440a5fd71a2c15c91b0