UCF STIG Viewer Logo
Changes are coming to https://stigviewer.com. Take our survey to help us understand your usage and how we can better serve you in the future.
Take Survey

Anonymous FTP must not be active on the system unless authorized.


Overview

Finding ID Version Rule ID IA Controls Severity
V-846 GEN004820 SV-846r2_rule ECSC-1 Medium
Description
Due to the numerous vulnerabilities inherent in anonymous FTP, it is recommended that it not be used. If anonymous FTP must be used on a system, the requirement must be authorized and approved in the system accreditation package.
STIG Date
Solaris 10 X86 Security Technical Implementation Guide 2014-04-04

Details

Check Text ( C-711r2_chk )
Attempt to log into this host with a user name of anonymous and a password of guest (also try the password of guest@mail.com). If the logon is successful, this is a finding.

Procedure:
# ftp localhost
Name: anonymous
530 Guest login not allowed on this machine.
Fix Text (F-1000r2_fix)
Configure the FTP service to not permit anonymous logins.