home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.security.misc
- Path: sparky!uunet!pmafire!mica.inel.gov!ux1!news.byu.edu!eff!sol.ctr.columbia.edu!spool.mu.edu!darwin.sura.net!convex!news.utdallas.edu!corpgate!bnrgate!bnr.co.uk!pipex!ibmpcug!gtoal
- From: gtoal@ibmpcug.co.uk (Graham Toal)
- Subject: Re: Grabbing your pw file from anonymous FTP
- Organization: The IBM PC User Group, UK.
- Date: Mon, 16 Nov 1992 00:17:31 GMT
- Message-ID: <Bxs8t8.Gp3@ibmpcug.co.uk>
- References: <83347@ut-emx.uucp>
- Lines: 23
-
- In article <83347@ut-emx.uucp> ifbb657@ccwf.cc.utexas.edu (Douglas Floyd) writes:
- > What keeps any person who can anonymous ftp from going down your
- >etc directory and grabbing the passwd file? Does ftp log this? I
- >know that some Unix systems use a chroot system to lock anonymous
- >ftp users into a restricted section of the directory. Do all
- >ftp systems do this?
-
- No, they don't all do it but you'd be hard pressed nowadays to find one
- that didn't. Anyway, most unixes are set up on the principle that
- people *can* snarf your password file. If you're a security-by-obscurity
- fanatic, you might as well go the whole hog and get a shadow password
- suite.
-
- On the flavour of unix that I run, I haven't worked out how to get
- it to log transfers except by turning ftpd debugging on (-d). A bit
- verbose, but it gives me what I want.
-
- (I have moral objections to logging anonymous ftp transfers on public
- sites, but this is *my* machine, and I have no public archives and
- no users who would be ftp'ing in)
-
- G
- --
-