STIGQter STIGQter: STIG Summary: Solaris 10 X86 Security Technical Implementation Guide Version: 2 Release: 2 Benchmark Date: 22 Jan 2021:

Anonymous FTP must not be active on the system unless authorized.

DISA Rule

SV-227853r603266_rule

Vulnerability Number

V-227853

Group Title

SRG-OS-000480

Rule Version

GEN004820

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Configure the FTP service to not permit anonymous logins.

Check Contents

Attempt to log into this host with a user name of anonymous and a password of guest (also try the password of guest@mail.com). If the logon is successful, this is a finding.

Procedure:
# ftp localhost
Name: anonymous
530 Guest login not allowed on this machine.

Vulnerability Number

V-227853

Documentable

False

Rule Version

GEN004820

Severity Override Guidance

Attempt to log into this host with a user name of anonymous and a password of guest (also try the password of guest@mail.com). If the logon is successful, this is a finding.

Procedure:
# ftp localhost
Name: anonymous
530 Guest login not allowed on this machine.

Check Content Reference

M

Target Key

4061

Comments