[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [cobalt-users] [raq4] FTP - Admin user denied ?!!?
- Subject: Re: [cobalt-users] [raq4] FTP - Admin user denied ?!!?
- From: "Wayne Sagar" <shortfork@xxxxxxxxxxx>
- Date: Sat Jan 5 03:30:01 2002
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
For the last few days when i log into the RAQ with user "admin" i have no
permissions to create, delete etc.... whats gone wrong?
Where to start.... If you've been ftp'ing in with admin password.. maybe
someone snatched that plain text admin level password and changed ownership
of the files..
ssh in and ls -al and see who owns the files in question.
If you're ftp'ing in as admin, my guess is, you have never changed the RaQ
default setup that comes with the admin and root password the same.. So if
someone got your admin password, they are now in as admin.. and also able to
log in as root.. bad!
ssh in,
su root
passwd
Make a cryptic password with mixed case, symbols, numbers etc something over
8 chars.. WRITE IT DOWN somewhere..
Now you have at least two levels of safety.
All of the above is moot if the "root" of your problem is that someone
besides you is living there as "root"..
Install ssh, disable telnet, NEVER log into an ftp account as server admin,
install self signed cert on your main site for the box so that any admin
commands/passwords are sent encrypted.
If all of the above has already been done by you, disregard, if none of the
above has been done, strongly suggest reading the archives here on security
issues. Most have been discussed at great length with installation
instructions etc..
Hope this helps and GOOD LUCK!
WS
_________________________________________________________________
Join the world?s largest e-mail service with MSN Hotmail.
http://www.hotmail.com