Is there a mission-critical reason for users to transfer files to/from their own accounts using FTP, rather than using a secure protocol like SCP/SFTP? If not, edit the vsftpd configuration file. Add or correct the following configuration option: 'local_enable=NO' If non-anonymous FTP logins are necessary, follow the guidance in the remainder of this section to secure these logins as much as possible. [yes/no] The use of non-anonymous FTP logins is strongly discouraged. Since SSH clients and servers are widely available, and since SSH provides support for a transfer mode which resembles FTP in user interface, there is no good reason to allow password-based FTP access. oval:org.secpod.oval:def:48387 oval:org.secpod.oval:def:48891 SCAP Repo OVAL Definition 2018-11-08