RE: ProFtpd question

2001-06-25 Thread buschjost
Just add DefaultRoot "~" to the proftpd.conf In this case it does not matter if your user has a shell or not! But better create ftp-users with no shell! Regards, Martin On 26-Jun-2001 Luc MAIGNAN wrote: > Hi, > > I use proftpd to allow users to connect to my server via ftp. I've de

Re: ProFtpd question

2001-06-25 Thread hpknight
Look up the DefaultRoot directive in the proftpd documentation. -hpknight On Tue, 26 Jun 2001, Luc MAIGNAN wrote: > Hi, > > I use proftpd to allow users to connect to my server via ftp. I've declared a > new user on my server, and set its home directory to /home/newuser. But in > this case, I

ProFtpd question

2001-06-25 Thread Luc MAIGNAN
Hi, I use proftpd to allow users to connect to my server via ftp. I've declared a new user on my server, and set its home directory to /home/newuser. But in this case, I have a security problem : when connected, the root directory for ftp is still :/home/newuser; so he can access the tree /home

Re: ProFtpd question

2001-06-25 Thread hpknight
Look up the DefaultRoot directive in the proftpd documentation. -hpknight On Tue, 26 Jun 2001, Luc MAIGNAN wrote: > Hi, > > I use proftpd to allow users to connect to my server via ftp. I've declared a > new user on my server, and set its home directory to /home/newuser. But in > this case,

ProFtpd question

2001-06-25 Thread Luc MAIGNAN
Hi, I use proftpd to allow users to connect to my server via ftp. I've declared a new user on my server, and set its home directory to /home/newuser. But in this case, I have a security problem : when connected, the root directory for ftp is still :/home/newuser; so he can access the tree /hom

Re: Compiling HostSentry

2001-06-25 Thread Gregoire Welraeds
According to man utmp on potato I386, PII: > # a) Size of utmp record (sizeof(struct utmp)) for your host. 384 > # b) Offset to tty field from beginning of record. 6 > # c) Length of tty field. 32 > # d) Offset to username field from beginning of record. 42 > # e) Length of username field. 32 > #

Re: Compiling HostSentry

2001-06-25 Thread Gregoire Welraeds
According to man utmp on potato I386, PII: > # a) Size of utmp record (sizeof(struct utmp)) for your host. 384 > # b) Offset to tty field from beginning of record. 6 > # c) Length of tty field. 32 > # d) Offset to username field from beginning of record. 42 > # e) Length of username field. 32 > #

Re: How to route

2001-06-25 Thread Jeff Coppock
See inline...jc Thusly Thwacked By Davy Gigan: > Marco Tassinari writes: > > > > > > Hallo, > > I wonder what is the best solution for security in this ascii-art > > network: > > > > > >[router] > > | > >[let's call it firewall even if it's n

Re: How to route

2001-06-25 Thread Davy Gigan
Marco Tassinari writes: > > > Hallo, > I wonder what is the best solution for security in this ascii-art > network: > > >[router] > | >[let's call it firewall even if it's not one for the moment] > | > +-

How to route

2001-06-25 Thread Marco Tassinari
Hallo, I wonder what is the best solution for security in this ascii-art network: [router] | [ ] | +--|-|| | | || [server]

Re: How to route

2001-06-25 Thread Jeff Coppock
See inline...jc Thusly Thwacked By Davy Gigan: > Marco Tassinari writes: > > > > > > Hallo, > > I wonder what is the best solution for security in this ascii-art > > network: > > > > > >[router] > > | > >[let's call it firewall even if it's

general question about login progs

2001-06-25 Thread Warren Turkal
Is the unix socket system secure enough that maybe you could run some kind of authentication daemon (pammish type thingy) and have the login progs authenticate against it using unix sockets? Then the authentication daemon could spawn the login shell? It would be another way to keep login prog fur

Re: How to route

2001-06-25 Thread Davy Gigan
Marco Tassinari writes: > > > Hallo, > I wonder what is the best solution for security in this ascii-art > network: > > >[router] > | >[let's call it firewall even if it's not one for the moment] > | > +

How to route

2001-06-25 Thread Marco Tassinari
Hallo, I wonder what is the best solution for security in this ascii-art network: [router] | [ ] | +--|-|| | | || [server]

general question about login progs

2001-06-25 Thread Warren Turkal
Is the unix socket system secure enough that maybe you could run some kind of authentication daemon (pammish type thingy) and have the login progs authenticate against it using unix sockets? Then the authentication daemon could spawn the login shell? It would be another way to keep login prog fu