Re: [BackupPC-users] security headaches

2009-09-25 Thread dan
I use iptables and allow access only from my workstation to the web interface, disable root and backuppc user's inbound ssh. I also limit inbound traffic with iptables so the backuppc must open the session to the client. -

Re: [BackupPC-users] security headaches

2009-09-25 Thread Tino Schwarze
On Fri, Sep 25, 2009 at 05:51:41AM -0400, Andrew Schulman wrote: > Here's my problem: I love having online backups, they're very > convenient. But they're a huge security problem. All of the LAN's > most sensitive files become readable by user backuppc, who can be > attacked through the web app

[BackupPC-users] security headaches

2009-09-25 Thread Andrew Schulman
Hi everyone. I'm a new BackupPC user, this is my first post here. Here's my problem: I love having online backups, they're very convenient. But they're a huge security problem. All of the LAN's most sensitive files become readable by user backuppc, who can be attacked through the web applicati