On Mon Aug 03 1998, C.J. Oster wrote:

> I don't know. All I did to break it was "chown root.ftp -R *", and
> it broke it.

Broken well and truely, by the sounds of it :)

NEVER give user "ftp" any sort of user/group ownership in the anonymous ftp
area!  It is a security hazzard.  (It opens the door to any anon user being
able to do things that should not be possible).

There is a USENET FAQ (try ftp://rtfm.mit.edu/pub/usenet/comp.security.unix/)
on how to go about setting up a secure anonymous ftp site in the correct
way.

Cheers
Tony

Reply via email to