Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

How do I disable anonymous FTP on an AIX Server

Posted on 2013-01-31
5
Medium Priority
?
2,707 Views
Last Modified: 2013-02-01
A recent security scan revealed that one of our servers is allowing anonymous FTP. I've been asked to disable anonymous FTP. To my knowledge, the absence of an "ftp" or "anonymous" login effectively disables that functionality. Neither of those accounts exist on the server. So, I'm in the dark as to what's raising the red flag.
0
Comment
Question by:babyb00mer
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 38842852
Hi,

AIX has a means of configuring anonymous FTP apart from just creating the userids "ftp" and "anonymous".

The clue is in the file /etc/ftpaccess.ctl

The directives "useronly:" and "grouponly:" in that file define anonymous users.

There are more directives like "puseronly:" and "pgrouponly:" which define anonymous users that are password protected.

"allow:" and "deny:" restrict host access, and "readonly:" or "writeonly:" configure directory access.

Please check your system for the presence of that file!
0
 

Author Comment

by:babyb00mer
ID: 38844410
This is the only record in the ftpaccess.ctl file:

pgrouponly: ftpguest

I documented the procedure for setting up anonymous users at our shop, but I didn't implement it on this particular server. I'm not sure why this would present a security problem.
0
 
LVL 68

Expert Comment

by:woolmilkporc
ID: 38844435
Members of the group ftpguest can access your server via FTP, but only after having entered the respective user password.

I assume that the pure existence of ftpaccess.ctl is considered a security risk by your security scanner, without taking a closer look into it.

"pgrouponly" in ftpaccess.ctl includes chrooting the concerned FTP users to their home directories, by the way.
0
 

Author Comment

by:babyb00mer
ID: 38844626
After inquiring further, I've determined that it's FTP in general that they're objecting to. For a more secure environment, they would prefer that we use sftp or scp.
0
 
LVL 68

Accepted Solution

by:
woolmilkporc earned 2000 total points
ID: 38844702
Well, might be a good idea.

Do you know how to disable FTP?

The easiest way is commenting out the line starting with "ftp" in /etc/inetd.conf and restarting inetd with "refresh -s inetd".

scp and sftp come with OpenSSH.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Java performance on Solaris - Managing CPUs There are various resource controls in operating system which directly/indirectly influence the performance of application. one of the most important resource controls is "CPU".   In a multithreaded…
Why Shell Scripting? Shell scripting is a powerful method of accessing UNIX systems and it is very flexible. Shell scripts are required when we want to execute a sequence of commands in Unix flavored operating systems. “Shell” is the command line i…
Learn how to navigate the file tree with the shell. Use pwd to print the current working directory: Use ls to list a directory's contents: Use cd to change to a new directory: Use wildcards instead of typing out long directory names: Use ../ to move…
In a previous video, we went over how to export a DynamoDB table into Amazon S3.  In this video, we show how to load the export from S3 into a DynamoDB table.
Suggested Courses

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question