Check: GEN005000
SUSE Linux Enterprise Server v11 for System z STIG:
GEN005000
(in versions v1 r12 through v1 r9)
Title
Anonymous FTP accounts must not have a functional shell. (Cat I impact)
Discussion
If an anonymous FTP account has been configured to use a functional shell, attackers could gain access to the shell if the account is compromised.
Check Content
Check the shell for the anonymous FTP account. Procedure: # grep "^ftp" /etc/passwd This is a finding if the seventh field is empty (the entry ends with a ':') or if the seventh field does not contain one of the following: /bin/false /dev/null /usr/bin/false /bin/true /sbin/nologin
Fix Text
Configure anonymous FTP accounts to use a non-functional shell. The Yast ‘Security and Users’ > ‘User and Group Management’ module can be used to configure the account. Or if necessary, edit the /etc/passwd file to remove any functioning shells associated with the ftp account and replace them with non-functioning shells, such as /bin/false.
Additional Identifiers
Rule ID: SV-45886r1_rule
Vulnerability ID: V-4387
Group Title: GEN005000
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000225 |
The organization employs the concept of least privilege, allowing only authorized accesses for users (and processes acting on behalf of users) which are necessary to accomplish assigned tasks in accordance with organizational missions and business functions. |
Controls
Number | Title |
---|---|
AC-6 |
Least Privilege |