2.2.9 Ensure FTP Server is not enabled

Information

The File Transfer Protocol (FTP) provides networked computers with the ability to transfer
files.

Rationale:

FTP does not protect the confidentiality of data or authentication credentials. It is
recommended SFTP be used if file transfer is required. Unless there is a need to run the
system as a FTP server (for example, to allow anonymous downloads), it is recommended
that the package be deleted to reduce the potential attack surface.

Solution

Run one of the following commands to disable vsftpd :

# chkconfig vsftpd off

# systemctl disable vsftpd

# update-rc.d vsftpd disable

Notes:

Additional methods of disabling a service exist. Consult your distribution documentation
for appropriate methods.

Additional FTP servers also exist and should be audited.

See Also

https://workbench.cisecurity.org/files/2420

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1, CSCv7|9.2

Plugin: Unix

Control ID: a0b302178ab3abc64cec05b4c0cef43a7d2bde2cc9bdec58841d37c908a66803