Check: 5.005
Windows Vista STIG:
5.005
(in versions v6 r42 through v6 r41)
Title
Installed FTP server is configured to allow access to the system drive. (Cat I impact)
Discussion
This is a Category 1 finding because the FTP service allows remote users to access shared files and directories which could provide access to system resources and compromise the system, especially if the user can gain access to the root directory of the boot drive.
Check Content
In the “Command Prompt” window, enter the following command, log on using an authenticated FTP account, and attempt to access the root of the boot drive: X:\>ftp 127.0.0.1 (Connected to ftru065103.ncr.disa.mil. 220 ftru065103 Microsoft FTP Service (Version 2.0).) User: ftpuser (331 Password required for ftpuser.) Password: password (230 User ftpuser logged in.) ftp> dir / If the FTP session indicates access to operating system files like “PAGEFILE.SYS” or “NTLDR,” then this is a finding.
Fix Text
Configure the system to prevent an FTP Service from allowing access to the system drive.
Additional Identifiers
Rule ID: SV-29496r1_rule
Vulnerability ID: V-1121
Group Title: FTP System File Access
Expert Comments
CCIs
Number | Definition |
---|---|
CCI-000366 |
The organization implements the security configuration settings. |
Controls
Number | Title |
---|---|
CM-6 |
Configuration Settings |