AlmaLinux OS 9 must not have any File Transfer Protocol (FTP) packages installed.
An XCCDF Rule
Description
Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. An FTP server provides an unencrypted file transfer mechanism that does not protect the confidentiality of user credentials or the remote session. If a privileged user were to log on using this service, the privileged user password could be compromised. SFTP or other encrypted file transfer methods must be used instead. Removing the server and client packages prevents inbound and outbound communications from being compromised.
- ID
- SV-269403r1050286_rule
- Version
- ALMA-09-037750
- Severity
- High
- References
- Updated
Remediation Templates
A Manual Procedure
Remove the default FTP client and server packages using the following command:
$ dnf remove vsftpd ftp