[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] Re: New Security Pkg for RaQ4



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

> anyone perhaps nobaloney.net can check what this package contain.

rpm -qpl proftpd-1.2.5-stackguardC1.i386.rpm yields:

/etc/ftpusers
/etc/logrotate.d/proftpd
/etc/xinetd.d/proftp
/usr/bin/ftpcount
/usr/bin/ftpwho
/usr/doc/proftpd-1.2.5
/usr/doc/proftpd-1.2.5/API
/usr/doc/proftpd-1.2.5/Configuration.html
/usr/doc/proftpd-1.2.5/GetConf
/usr/doc/proftpd-1.2.5/PFTEST.conf.in
/usr/doc/proftpd-1.2.5/PFTEST.group
/usr/doc/proftpd-1.2.5/PFTEST.install
/usr/doc/proftpd-1.2.5/PFTEST.passwd
/usr/doc/proftpd-1.2.5/PFTEST.shadow
/usr/doc/proftpd-1.2.5/README
/usr/doc/proftpd-1.2.5/README.AIX
/usr/doc/proftpd-1.2.5/README.FreeBSD
/usr/doc/proftpd-1.2.5/README.LDAP
/usr/doc/proftpd-1.2.5/README.PAM
/usr/doc/proftpd-1.2.5/README.Solaris2.5x
/usr/doc/proftpd-1.2.5/README.Unixware
/usr/doc/proftpd-1.2.5/README.linux-privs
/usr/doc/proftpd-1.2.5/README.mod_sql
/usr/doc/proftpd-1.2.5/README.mod_wrap
/usr/doc/proftpd-1.2.5/README.modules
/usr/doc/proftpd-1.2.5/README.ports
/usr/doc/proftpd-1.2.5/README.ratio
/usr/doc/proftpd-1.2.5/ShowUndocumented
/usr/doc/proftpd-1.2.5/anonymous.conf
/usr/doc/proftpd-1.2.5/basic.conf
/usr/doc/proftpd-1.2.5/complex-virtual.conf
/usr/doc/proftpd-1.2.5/development.notes
/usr/doc/proftpd-1.2.5/faq.html
/usr/doc/proftpd-1.2.5/license.txt
/usr/doc/proftpd-1.2.5/mod_sample.c
/usr/doc/proftpd-1.2.5/mod_sql.conf
/usr/doc/proftpd-1.2.5/rfc
/usr/doc/proftpd-1.2.5/rfc/draft-bonachea-sftp-00.txt
/usr/doc/proftpd-1.2.5/rfc/draft-ietf-ftpext-mlst-15.txt
/usr/doc/proftpd-1.2.5/rfc/draft-ietf-ftpext-sec-consider-02.txt
/usr/doc/proftpd-1.2.5/rfc/rfc0959.txt
/usr/doc/proftpd-1.2.5/rfc/rfc2228.txt
/usr/doc/proftpd-1.2.5/virtual.conf
/usr/doc/proftpd-1.2.5/xferstats.holger-preiss
/usr/man/man1/ftpcount.1
/usr/man/man1/ftpwho.1
/usr/man/man5/xferlog.5
/usr/man/man8/ftpshut.8
/usr/man/man8/proftpd.8
/usr/sbin/ftpshut
/usr/sbin/in.proftpd
/usr/sbin/proftpd
/var/run/proftpd

There is a script named 10_ftpusers.pl that runs post-install, which 
contains this comment block at the top:

#!/usr/bin/perl
# $Id: 10_ftpusers.pl,v 1.4 2002/09/30 19:48:01 jthrowe Exp $
#
# Name: 10_ftpusers.pl
# Date: 9/16/2002
#
# Description: This perl script verifies /etc/ftpusers after the
# install of proftpd.
#
# If /etc/ftpusers is modified prior to the install, then RPM will NOT
# overwrite it when the new proftpd is installed.  Instead it will
# leave /etc/ftpusers alone and install the new /etc/ftpusers as
# /etc/ftpusers.rpmnew.
#
# If the original /etc/ftpusers was unmodified, then the new proftpd
# will install the correct /etc/ftpusers file and /etc/ftpusers.rpmnew
# won't be created.
#
# In the interest of security users should get the correct set of
# users in /etc/ftpusers.  Thus if /etc/ftpusers is a subset of
# /etc/ftpusers.rpmnew, then /etc/ftpusers.rpmnew is copied over
# /etc/ftpusers.  Otherwise, /etc/ftpusers is left alone.

As you can see by the CVS date string (when this file was last checked 
in), the QA backlog is apparently running about 5 months now... :)

Note - The current stable version of ProFTPd is 1.2.7; it's unknown 
right now what has been backported into this 1.2.5 version.

- -- 
Bruce Timberlake

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.1 (GNU/Linux)

iD8DBQE+S/dkvLA2hUZ9kgwRAmKYAJ9U7bKeMBi5Mw+Itw36EugW736FfACffxVy
5RYFtu4sgJJmbkjalDbyqzE=
=KX3N
-----END PGP SIGNATURE-----