Check: GEN004820
Solaris 10 SPARC STIG:
GEN004820
(in versions v2 r4 through v1 r19)
Title
Anonymous FTP must not be active on the system unless authorized. (Cat II impact)
Discussion
Due to the numerous vulnerabilities inherent in anonymous FTP, it is recommended that it not be used. If anonymous FTP must be used on a system, the requirement must be authorized and approved in the system accreditation package.
Check Content
Attempt to log into this host with a user name of anonymous and a password of guest (also try the password of guest@mail.com). If the logon is successful, this is a finding. Procedure: # ftp localhost Name: anonymous 530 Guest login not allowed on this machine.
Fix Text
Configure the FTP service to not permit anonymous logins.
Additional Identifiers
Rule ID: SV-226946r603265_rule
Vulnerability ID: V-226946
Group Title: SRG-OS-000480
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |