Re: FTP security question...

2002-11-16 Thread phani
On Sat, Nov 16, 2002 at 07:02:23AM +, [EMAIL PROTECTED] wrote: > On Wed, Nov 13, 2002 at 11:08:52AM -0600, Mike Cain wrote: > hi, >Anon root is fine with a locked down root. But you should take care to check if >there are any exploits on ur ftp server (wu-ftp ???). Check up if there are an

RE: FTP security question...

2002-11-16 Thread The Crocodile
Many of the remotely exploitable bugs found in FTPD programs require a valid login to be able to overflow the buffer and thus exploit the vulnerability. If you have anon turned on and don't need it you leave that avenue of attack open. If for some reason you REQUIRE that it be left open then do s