2.2.6 Ensure ftp client is not installed

Information

Several FTP-family client packages may be available on Debian / Ubuntu systems:

- ftp / tnftp - tnftp is an enhanced FTP client; ftp is the historic Internet-standard FTP client. Both provide interactive file transfer to remote network sites.
- inetutils-ftp - the FTP client from the GNU inetutils suite, an alternative to tnftp.
- ftp-ssl - a TLS-wrapped FTP client (legacy; superseded by FTPS-capable replacements).
- atftp - the Advanced Trivial File Transfer Protocol client. Although TFTP differs from full FTP, the package family historically belongs to the "FTP client" category and is commonly removed alongside the others as part of the same hardening intent.

Unless there is a documented need to run any of these clients (for example, to retrieve build artifacts from a legacy FTP-only mirror), it is recommended that all FTP-family client packages be removed to reduce the potential attack surface and prevent users from inadvertently sending credentials over an unencrypted transport.

Unless there is a need to run the system using Internet standard File Transfer Protocol (for example, to allow anonymous downloads), it is recommended that the package be removed to reduce the potential attack surface.

Solution

Run the following command to uninstall and purge every FTP-family client package that is installed:

# apt purge ftp tnftp atftp inetutils-ftp ftp-ssl

Impact:

Many insecure service clients are used as troubleshooting tools and in testing environments. Uninstalling them can inhibit capability to test and troubleshoot. If they are required it is advisable to remove the clients after use to prevent accidental or intentional misuse. Modern alternatives ( curl, wget, sftp, scp, rsync over SSH) cover the legitimate file-transfer use cases without exposing credentials or data in cleartext.

See Also

https://workbench.cisecurity.org/benchmarks/27798