I gave ftp a /bin/bash shell and it works, but is this a security risk ?
-----Original Message-----
From: [EMAIL PROTECTED]
[mailto:[EMAIL PROTECTED]]On Behalf Of Peter McCarthy
Sent: Tuesday, April 04, 2000 7:25 PM
To: Linux Sydney (E-mail)
Subject: RE: [SLUG] ProFtp anon access
I added this to the /etc/passwd file but no effect. any other ideas ?
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of
Dean Hamstead
Sent: Tuesday, April 04, 2000 6:23 PM
To: [EMAIL PROTECTED]
Cc: Linux Sydney (E-mail)
Subject: Re: [SLUG] ProFtp anon access
By the look of things the ftp user needs a valid shell
/bin/nologin is common, just sh script saying "go away" basically
Dean
Peter McCarthy wrote:
>
> I'm trying to setup Proftp on my RH61 box but am having trouble with the
config
> for some reason I keep getting the following error in /var/log/secure when I
try
> to login as ftp
>
> Apr 4 17:09:34 mail proftpd[690]: mail.asap.net.au (asx[192.168.0.1]) - USER
> ftp (Login failed): Invalid shell.
>
> Normal User login works fine ?
>
> Help appreciated, thanx
>
> Peter McCarthy
>
> # This is a basic ProFTPD configuration file (rename it to
> # 'proftpd.conf' for actual use. It establishes a single server
> # and a single anonymous login. It assumes that you have a user/group
> # "nobody" and "ftp" for normal operation and anon.
>
> ServerName "ProFTPD For ASAP and DVA"
> ServerType inetd
> DefaultServer on
>
> # Port 21 is the standard FTP port.
> Port 21
> # Umask 022 is a good standard umask to prevent new dirs and files
> # from being group and world writable.
> Umask 022
>
> # To prevent DoS attacks, set the maximum number of child processes
> # to 30. If you need to allow more than 30 concurrent connections
> # at once, simply increase this value. Note that this ONLY works
> # in standalone mode, in inetd mode you should use an inetd server
> # that allows you to limit maximum number of processes per service
> # (such as xinetd)
> MaxInstances 30
>
> # Set the user and group that the server normally runs at.
> User nobody
> Group nobody
>
> # Set the maximum number of seconds a data connection is allowed
> # to "stall" before being aborted.
> TimeoutStalled 300
>
> # Normally, we want files to be overwriteable.
> <Directory /*>
> AllowOverwrite on
> </Directory>
>
> # A basic anonymous configuration, no upload directories.
> <Anonymous ~ftp>
>
> # Allow logins if they are disabled above.
> <Limit LOGIN>
> AllowAll
> </Limit>
>
> User ftp
> Group ftp
> # We want clients to be able to login with "anonymous" as well as "ftp"
> UserAlias anonymous ftp
>
> # Limit the maximum number of anonymous logins
> MaxClients 10 "Sorry, max %m users -- try again later"
>
> # We want 'welcome.msg' displayed at login, and '.message' displayed
> # in each newly chdired directory.
> DisplayLogin welcome.msg
> DisplayFirstChdir .message
>
> # Limit WRITE everywhere in the anonymous chroot
> <Limit WRITE>
> DenyAll
> </Limit>
>
> # An upload directory that allows storing files but not retrieving
> # or creating directories.
> <Directory uploads/*>
> <Limit READ>
> DenyAll
> </Limit>
>
> <Limit STOR>
> AllowAll
> </Limit>
> </Directory>
> </Anonymous>
>
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text
--
BONG: http://bong.pnc.com.au
LANZAC: http://bong.pnc.com.au/lanzac
EMAIL: [EMAIL PROTECTED],[EMAIL PROTECTED]
ICQ: 16867613
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text