Skip to content

AlmaLinux OS 9 must not have any File Transfer Protocol (FTP) packages installed.

An XCCDF Rule

Description

Passwords must be protected at all times, and encryption is the standard method for protecting passwords. If passwords are not encrypted, they can be plainly read (i.e., clear text) and easily compromised. An FTP server provides an unencrypted file transfer mechanism that does not protect the confidentiality of user credentials or the remote session. If a privileged user were to log on using this service, the privileged user password could be compromised. SFTP or other encrypted file transfer methods must be used instead. Removing the server and client packages prevents inbound and outbound communications from being compromised.

ID
SV-269403r1050286_rule
Version
ALMA-09-037750
Severity
High
References
Updated

Remediation Templates

A Manual Procedure

Remove the default FTP client and server packages using the following command:

$ dnf remove vsftpd ftp