Check: GEN004840
HP-UX 11.23 STIG:
GEN004840
(in version v1 r8)
Title
If the system is an anonymous FTP server, it must be isolated to the DMZ network. (Cat II impact)
Discussion
Anonymous FTP is a public data service which is only permitted in a server capacity when located on the DMZ network.
Check Content
Use the command ftp to connect the system's FTP service. Attempt to log into this host with a user name of anonymous and a password of guest (also try the password of guest@mail.com). If the logon is not successful, this check is not applicable. # ftp localhost OR # ftp `hostname` Ask the SA if the system is located on a DMZ network. If the system is not located on a DMZ network, this is a finding.
Fix Text
Move the system to a DMZ network.
Additional Identifiers
Rule ID: SV-35101r1_rule
Vulnerability ID: V-4702
Group Title: GEN004840
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000787 |
The organization manages information system identifiers for users and devices by selecting an identifier that uniquely identifies a device. |
Controls
Number | Title |
---|---|
No controls are assigned to this check |