Finding ID | Version | Rule ID | IA Controls | Severity |
---|---|---|---|---|
V-4388 | GEN005020 | SV-38887r1_rule | ECSC-1 | Medium |
Description |
---|
If an anonymous FTP account does not use a chroot or similarly isolated environment, the system may be more vulnerable to exploits against the FTP service. Such exploits could allow an attacker to gain shell access to the system and view, edit, or remove sensitive files. |
STIG | Date |
---|---|
Draft AIX Security Technical Implementation Guide | 2011-08-17 |
Check Text ( C-37887r1_chk ) |
---|
Consult vendor documentation for the anonymous FTP service to determine the necessary configuration for operating the service in a chroot environment. If the system is not configured to operate the anonymous FTP service in a chroot environment, this is a finding. |
Fix Text (F-33133r1_fix) |
---|
Configure the anonymous FTP service to operate in a chroot environment. Consult the following resources for setting up anonymous ftp. # more /usr/samples/tcpip/anon.users.ftp Web link: http://publib.boulder.ibm.com/infocenter/pseries/v5r3/index.jsp?topic=/com.ibm.aix.security/doc/security/HT_security_anonymous_ftp.htm |