I gave ftp a /bin/bash shell and it works, but is this a security risk ?

-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Peter McCarthy
Sent: Tuesday, April 04, 2000 7:25 PM
To: Linux Sydney (E-mail)
Subject: RE: [SLUG] ProFtp anon access


I added this to the /etc/passwd file but no effect.  any other ideas ?

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of
Dean Hamstead
Sent: Tuesday, April 04, 2000 6:23 PM
To: [EMAIL PROTECTED]
Cc: Linux Sydney (E-mail)
Subject: Re: [SLUG] ProFtp anon access


By the look of things the ftp user needs a valid shell
/bin/nologin is common, just sh script saying "go away" basically

Dean

Peter McCarthy wrote:
>
> I'm trying to setup Proftp on my RH61 box but am having trouble with the
config
> for some reason I keep getting the following error in /var/log/secure when I
try
> to login as ftp
>
> Apr  4 17:09:34 mail proftpd[690]: mail.asap.net.au (asx[192.168.0.1]) - USER
> ftp (Login failed): Invalid shell.
>
> Normal User login works fine ?
>
> Help appreciated, thanx
>
> Peter McCarthy
>
> # This is a basic ProFTPD configuration file (rename it to
> # 'proftpd.conf' for actual use.  It establishes a single server
> # and a single anonymous login.  It assumes that you have a user/group
> # "nobody" and "ftp" for normal operation and anon.
>
> ServerName                      "ProFTPD For ASAP and DVA"
> ServerType                      inetd
> DefaultServer                   on
>
> # Port 21 is the standard FTP port.
> Port                            21
> # Umask 022 is a good standard umask to prevent new dirs and files
> # from being group and world writable.
> Umask                           022
>
> # To prevent DoS attacks, set the maximum number of child processes
> # to 30.  If you need to allow more than 30 concurrent connections
> # at once, simply increase this value.  Note that this ONLY works
> # in standalone mode, in inetd mode you should use an inetd server
> # that allows you to limit maximum number of processes per service
> # (such as xinetd)
> MaxInstances                    30
>
> # Set the user and group that the server normally runs at.
> User                            nobody
> Group                           nobody
>
> # Set the maximum number of seconds a data connection is allowed
> # to "stall" before being aborted.
> TimeoutStalled                  300
>
> # Normally, we want files to be overwriteable.
> <Directory /*>
>   AllowOverwrite                on
> </Directory>
>
> # A basic anonymous configuration, no upload directories.
> <Anonymous ~ftp>
>
>   # Allow logins if they are disabled above.
>   <Limit LOGIN>
>     AllowAll
>   </Limit>
>
>   User                          ftp
>   Group                         ftp
>   # We want clients to be able to login with "anonymous" as well as "ftp"
>   UserAlias                     anonymous ftp
>
>   # Limit the maximum number of anonymous logins
>   MaxClients                    10 "Sorry, max %m users -- try again later"
>
>   # We want 'welcome.msg' displayed at login, and '.message' displayed
>   # in each newly chdired directory.
>   DisplayLogin                  welcome.msg
>   DisplayFirstChdir             .message
>
>   # Limit WRITE everywhere in the anonymous chroot
>   <Limit WRITE>
>     DenyAll
>   </Limit>
>
>   # An upload directory that allows storing files but not retrieving
>   # or creating directories.
>   <Directory uploads/*>
>     <Limit READ>
>       DenyAll
>     </Limit>
>
>     <Limit STOR>
>       AllowAll
>     </Limit>
>   </Directory>
> </Anonymous>
>
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text

--
BONG: http://bong.pnc.com.au
LANZAC: http://bong.pnc.com.au/lanzac
EMAIL: [EMAIL PROTECTED],[EMAIL PROTECTED]
ICQ: 16867613

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to