Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

sublogin in anonymous ftp using user command

Posted on 1998-10-12
6
Medium Priority
?
482 Views
Last Modified: 2013-12-23
With  wu-ftpd,  when  anonymous  users  ftp in  and  try a
sublogin with the "user"  command, they get this  message:
Can't change user from guest login.

Is there a way to allow sublogins for anonymous ftp?

Are there any  security  issues by allowing  sublogins  in
anonymous ftp?.
0
Comment
Question by:dhana
6 Comments
 

Author Comment

by:dhana
ID: 1582436
Edited text of question
0
 

Author Comment

by:dhana
ID: 1582437
Expecting the answer?
0
 
LVL 2

Expert Comment

by:squint
ID: 1582438
# man ftpaccess

....

     guestgroup <groupname> [<groupname> ...]
          If a REAL user is a member of any of  <groupname>,  the
          session  is  set  up exactly as with anonymous FTP.  In
          other words, a chroot() is done, and  the  user  is  no
          longer  permitted  to issue the USER and PASS commands.
          <groupname> is a valid group from /etc/group (or  wher-
          ever your getgrent() call looks).

....


0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
LVL 7

Expert Comment

by:HalldorG
ID: 1582439
ftp -n machine then you can do user after you get the connection
0
 

Author Comment

by:dhana
ID: 1582440
If ftp is invoked with -n option, no other command is executed
in the ftp session. For example,

ftp1:root> ftp -n ftp1
Connected to ftp1.india.hp.com.
220 ftp1.india.hp.com FTP server (Version 1.1.214.2 Tue Nov  3 06:02:05 GMT 1998
) ready.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> pwd
530 Please login with USER and PASS.

In bove example, the only option is, after entering into the ftp seesion, immediately user has to issue the "user" to command to execute any command.

The user has to execute series of command in the ftp session, and then has to issue the "user" command.
0
 
LVL 1

Accepted Solution

by:
dotand earned 40 total points
ID: 1582441
The restriction against sub-login in guest mode is intended. Itherwise I could login to your server as anonymopus and start using the USER command to attempt cracking your system.
Because I'll allrerady be logged and there is no loggin information that is gathered and examined dynamically I'll be set to break your system.

Better that you stick to the old method of letting the users login as usual. If you fear for people grabbing the passwords over the net move to a one time password system or use encrypted connections.

If you will give moire information maybe somebody can tailor a solution to your particular ituation.

HTH,
Dotan
 
0

Featured Post

Get your Disaster Recovery as a Service basics

Disaster Recovery as a Service is one go-to solution that revolutionizes DR planning. Implementing DRaaS could be an efficient process, easily accessible to non-DR experts. Learn about monitoring, testing, executing failovers and failbacks to ensure a "healthy" DR environment.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will inform Clients about common and important expectations from the freelancers (Experts) who are looking at your Gig.
During and after that shift to cloud, one area that still poses a struggle for many organizations is what to do with their department file shares.
Internet Business Fax to Email Made Easy - With  eFax Corporate (http://www.enterprise.efax.com), you'll receive a dedicated online fax number, which is used the same way as a typical analog fax number. You'll receive secure faxes in your email, f…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…

782 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question