GEN005120 - The TFTP daemon must be configured to vendor specifications, including a dedicated TFTP user account, a non-login shell, such as /bin/false, and a home directory owned by the TFTP user.

Information

If TFTP has a valid shell, it increases the likelihood of someone logging to the TFTP account and compromising the system.

Solution

Create a TFTP user account if none exists.
Assign a non-login shell to the TFTP user account, such as /bin/false.
Assign a home directory to the TFTP user account.

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_SOL_10_x86_V2R4_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-220105r603266_rule, STIG-ID|GEN005120, STIG-Legacy|SV-39825, STIG-Legacy|V-849, Vuln-ID|V-220105

Plugin: Unix

Control ID: 441c7922d6b5c0ad875ce9feed445cf7f021b7ec952fcf85af3e6534fb80bf72