GEN004900 - The ftpusers file must contain account names not allowed to use FTP.

Information

The ftpusers file contains a list of accounts that are not allowed to use FTP to transfer files. If the file does not contain the names of all accounts not authorized to use FTP, then unauthorized use of FTP may take place.

Solution

Add accounts not allowed to use FTP to the /etc/ftpd/ftpusers file.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_SPARC_V2R4_STIG.zip

Item Details

Category: ACCESS CONTROL

References: 800-53|AC-3(4), CAT|II, CCI|CCI-002165, Rule-ID|SV-226949r854440_rule, STIG-ID|GEN004900, STIG-Legacy|SV-28407, STIG-Legacy|V-841, Vuln-ID|V-226949

Plugin: Unix

Control ID: 206ea100159bccfb924542e50fde4044337ffd2f6349fe920c7c05195582af73