Check: GEN005020
VMware ESX 3 Server:
GEN005020
(in version v1 r2)
Title
The anonymous FTP account must be configured to use chroot or a similarly isolated environment. (Cat II impact)
Discussion
If an anonymous FTP account does not use a chroot or similarly isolated environment, the system may be more vulnerable to exploits against the FTP service. Such exploits could allow an attacker to gain shell access to the system and view, edit, or remove sensitive files.
Check Content
Consult vendor documentation for the anonymous FTP service to determine the necessary configuration for operating the service in a chroot environment. If the system is not configured to operate the anonymous FTP service in a chroot environment, this is a finding.
Fix Text
Configure the anonymous FTP service to operate in a chroot environment. Consult vendor documentation for the necessary configuration procedures.
Additional Identifiers
Rule ID: SV-4388r2_rule
Vulnerability ID: V-4388
Group Title: GEN005020
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
Implement the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |