Solved

anonymous ftp server

Posted on 2001-08-24
9
392 Views
Last Modified: 2010-03-18
hello there,

i'm running Mandrake 7.2 and have just set up an anonymous ftp server.

when i tried to test if it works by "ftp localhost", i got "ftp: connect: Connection refused". I followed exactly a classic UNIX book, so i have no idea what went wrong...

your comments will be very much appreciated!

ken
(more points will be offered depends on how well you answer this question. Thanks a lot!)
0
Comment
Question by:ken021600
  • 5
  • 4
9 Comments
 
LVL 1

Expert Comment

by:dkloes
Comment Utility
Are there any ftp related messages in /var/log/messages?  Otherwise, we will need more information on your setup since we don't know what your reference says for ftp setup.  I am assuming you have network connectivity (i.e. ping localhost works), that the ftp server daemon has been configured, and the ftp home directory exists.  Any other information you can provide would be helpful.
0
 

Author Comment

by:ken021600
Comment Utility
Thank you for your reply. Actually I've figured it out. So now I can run it properly.
So can you ask another question which has something to do with anonymous ftp server? The 50 points will be yours if you can help me out:

why do I have to set /home/ftp directory to be owned by root and it should not be writeable by anyone? and why should the "ls" command in the /home/ftp/bin have permission 111 only?

thanks a lot,
ken
0
 
LVL 1

Expert Comment

by:dkloes
Comment Utility
ls is owned by root with permissions 111 (noread, nowrite, execute).  Other commands in /home/ftp/bin should have the same permissions as well.  This allows users to execute the commands but not be able to read or write them as a security measure.

The /home/ftp directory is the "root" directory for an anonymous user.  This prevents anonymous users from going anywhere on the system except that directory.  It is owned by root with the same group as ftp.  The owner permissions are for root and group permissions are for the anonymous users.   The permissions should be 555 (read, nowrite, execute).
0
 

Author Comment

by:ken021600
Comment Utility
thanks for your reply.

"Other commands in /home/ftp/bin should have the same permissions as well.  This allows users to execute the commands but not be able to read or write them as a security measure."

but files like "/home/ftp/bin/ls" are unreadable! what damage can hackers do if i set that file to have 555 permission??
0
How your wiki can always stay up-to-date

Quip doubles as a “living” wiki and a project management tool that evolves with your organization. As you finish projects in Quip, the work remains, easily accessible to all team members, new and old.
- Increase transparency
- Onboard new hires faster
- Access from mobile/offline

 

Author Comment

by:ken021600
Comment Utility
hellooo there,

can you answer my question?

thanks
ken
0
 
LVL 1

Expert Comment

by:dkloes
Comment Utility
Using the principle of least privilege, why would you want to give someone more access then they need?  Unless there is a reason why you would want to give someone read permission on an executable file, don't take any chances.  
0
 
LVL 1

Accepted Solution

by:
dkloes earned 50 total points
Comment Utility
In addition to being able to read a file, read permission also gives permission to copy it.  All resources that I checked recommend 111 permissions on ftp bin files.  Although not expressly stated, it just makes sense to not grant permissions that are not needed.
0
 

Author Comment

by:ken021600
Comment Utility
ok, i'll give you an A and 50 points.

thanks,
ken
0
 
LVL 1

Expert Comment

by:dkloes
Comment Utility
Thanx.
BTW:  You would be surprised what I have learned over the years by looking at the ASCII readable portions of an executable file.
0

Featured Post

Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

Join & Write a Comment

I have seen several blogs and forum entries elsewhere state that because NTFS volumes do not support linux ownership or permissions, they cannot be used for anonymous ftp upload through the vsftpd program.   IT can be done and here's how to get i…
Note: for this to work properly you need to use a Cross-Over network cable. 1. Connect both servers S1 and S2 on the second network slots respectively. Note that you can use the 1st slots but usually these would be occupied by the Service Provide…
This tutorial demonstrates a quick way of adding group price to multiple Magento products.
You have products, that come in variants and want to set different prices for them? Watch this micro tutorial that describes how to configure prices for Magento super attributes. Assigning simple products to configurable: We assigned simple products…

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

12 Experts available now in Live!

Get 1:1 Help Now