WU-FTPD 2.6 Security Problem

WU-FTPD 2.6 Security Problem

Post by Egon Rat » Fri, 10 Mar 2000 04:00:00



Hi!

I am running a FreeBSD Box with WU-FTPD 2.6. The Problem is, that
users can retrieve files, that are marked as nonretrievable in the
ftpaccess. For example:

noretrieve /etc class=inet

But a user in the class inet can retrieve files like /etc/pwd.db.
Whats wrong?

Bye,

Egon

 
 
 

1. where to find WU-FTPD 2.6 for sparc-solaris 2.6 (binary)?

 hi all,
Can anyone tell me where can i find a binary of WU-ftpd version 2.6
for Sparc-solaris 2.6? I searched in sunfreewre and metalab.unc.edu but
I found only the 2.4 version.
 any help could be so appreciated.
--
**********************************************************************

* I.A.V Hassan II................* GSM:+212-1-74-20-71               *
* Rabat-Instituts, Morocco.......* Tel:+212-7-77-17-58/59/45         *
* "handsome is as hansome does"..* Fax:+212-7-77-81-35               *
**********************************************************************

2. Eudora and POP-3

3. wu-ftpd 2.6 with RH7.0 timeout problems

4. RH5 Installation via PLIP

5. wu-ftpd, Solaris 2.6, compile trouble

6. Big -noisebox VB code

7. wu-ftpd 2.6 connects slow

8. UPS Support in 1.3.2

9. Does anonymous wu-ftpd work on Solaris 2.6?

10. solaris 2.6 package of wu-ftpd 2.6.0 with large file support

11. Sec. Vulnerability with WU-FTPD 2.6

12. wu-ftpd on solaris sparc 2.6

13. wu-ftpd in Solaris 2.6