[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] Pro-FTP install



Kim Emax wrote:

> I just know that I while, checking for security issues, found that I, as anonymous, could download htpasswd and htgroup, which is not very interesting :-(

Anonymous logins, on a properly configured and non-hacked RaQ, should
only be able to download the contents of /home/sites/siteX/ftp, and
should NOT be able to download the contents of
/home/sites/siteX/ftp/incoming.

If you're able to do anything else while logged in as anonymous, you've
got a machine that either you or someone else has hacked.

> And I live and was born in Copenhagen, Denmark :-)

I'll try to not hold that against you <smile>.

> Sincerly
> kim
-- 
Jeff Lasman <jblists@xxxxxxxxxxxxx>
Linux and Cobalt/Sun/RaQ Consulting
nobaloney.net, P. O. Box 52672, Riverside, CA  92517
voice: +1 909 778-9980  *  fax: +1 909 548-9484