GEN005120 - The TFTP daemon must be configured to vendor specifications, including a dedicated TFTP user account, a non-login shell such as /bin/false, and a home directory owned by the TFTP user.

Information

If TFTP has a valid shell, it increases the likelihood someone could log on to the TFTP account and compromise the system.

Solution

Configure TFTP to use a dedicated 'tftp' user.

Procedure:
Create a dedicated 'tftp' user account if none exists.

Assign a non-login shell to the 'tftp' user account, such as /bin/false.

Assign a home directory to the 'tftp' user account.

Edit /etc/xinetd.d/tftp to have 'tftp' as the value of the 'user' parameter.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_Oracle_Linux_5_V2R1_STIG.zip

Item Details

Category: ACCESS CONTROL, SYSTEM AND COMMUNICATIONS PROTECTION

References: 800-53|AC-6, 800-53|SC-4, CAT|II, CCI|CCI-000225, CCI|CCI-001090, Rule-ID|SV-218568r603259_rule, STIG-ID|GEN005120, STIG-Legacy|SV-63159, STIG-Legacy|V-849, Vuln-ID|V-218568

Plugin: Unix

Control ID: 780677618ff63a24c0191407e38696bd60562f7bd62366051ffd7791982be10c