If you have installed fsp and an FTP daemon, and do not want to have anonymous FTP enabled, you should remove the "ftp" account. This can be done with the command "userdel ftp".
Please note that if you use proftpd as the FTP daemon this flaw will not affect you, since it required one to enable anonymous FTP manually.
We have fixed this in fsp 2.71-10. Please note that if you have already installed fsp, upgrading to this version will not remove the user "ftp", you will have to do manually.