hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : wu-ftp user rights
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

wu-ftp user rights

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 07-17-2004, 07:08 PM
vanHelsing vanHelsing is offline
WHT Addict
 
Join Date: Apr 2004
Posts: 148

wu-ftp user rights


My users are now able to download some OS files and other users files, nothing critical to system tho. Is this security hole that i missed or an feature?

If its a feature, how can i set that users dont have any rights outside /home/myaccount. I know that chroot is an option, but i dont care if users can see files, i only want to prevent access those file.

Debian Stable
wu-ftp 2.6.2

Reply With Quote


Sponsored Links
  #2  
Old 07-17-2004, 09:47 PM
eth00 eth00 is offline
Web Hosting Master
 
Join Date: Apr 2003
Location: NC
Posts: 2,911
Not sure what wu-ftp calls it but the feature you are looking for is a chroot. There should be something in the config where you can chroot the users to their home directory.

If you do not set the option wu-ftpd and proftpd both allow access to / if the chmod allows it.

__________________
John W
www.eth0.us

Reply With Quote
  #3  
Old 07-18-2004, 12:51 AM
vanHelsing vanHelsing is offline
WHT Addict
 
Join Date: Apr 2004
Posts: 148
OK, ill try to dig something up.

Reply With Quote
Sponsored Links
  #4  
Old 07-18-2004, 11:31 PM
hiryuu hiryuu is offline
Web Hosting Master
 
Join Date: Jan 2003
Posts: 1,715
Don't use wu-ftpd. Its security history is beyond redemption, and better packages (proftpd was mentioned, and I like vsftpd) are readily available.

__________________
Game Servers are the next hot market!
Slim margins, heavy support, fickle customers, and moronic suppliers!
Start your own today!

Reply With Quote
  #5  
Old 07-19-2004, 11:59 AM
sonic10 sonic10 is offline
WHT Addict
 
Join Date: Apr 2002
Location: USA
Posts: 117
I agree with hiryuu that wu-ftpd is not good since it is open to many exploits. Proftpd will do what you want to do with ease.

Reply With Quote
  #6  
Old 07-22-2004, 05:41 PM
vanHelsing vanHelsing is offline
WHT Addict
 
Join Date: Apr 2004
Posts: 148
Post

Nice, how do i do it with ProFTP

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
50ee1bfd-fc2c-4c2a-923c-1a1745a79962 Listing 2013-03-05 18:25:35
Web Host SingleHop Adds New Automated Features to its Service Level Agreement Web Hosting News 2012-04-23 09:50:45
W3C Online Privacy Standards Draft Defines Online Tracking Preferences Web Hosting News 2011-11-15 22:03:45
GlobalSign Launches Enterprise Managed SSL Platform v2.0 Web Hosting News 2011-09-01 15:12:30
IT Management Software Firm SolarWinds Launches Synthetic End User Monitor Web Hosting News 2011-08-19 18:46:21


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?