2.3 Only enable FTP if absolutely necessary - Uncomment service ftp in /etc/inet/inetd.conf

Information

Like telnet, the FTP protocol is unencrypted, which means passwords and other data transmitted during the session can captured by sniffing the network, and that the FTP session itself can be hijacked by an external attacker. SSH provides two different encrypted file transfer mechanisms.scp and sftp.and should be used instead.

See Also

https://workbench.cisecurity.org/files/633

Item Details

Audit Name: CIS Solaris 9 v1.3

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-7b., CSCv6|9.1

Plugin: Unix

Control ID: b14f881817399e82e219130323a663ad9edfef8276ede134f5cbd32688194c66