secure ftp

secure ftp

Post by <kim.. » Sat, 15 Dec 2001 02:13:30



If anyone out there runs an ftp server, I would appreciate any opinions on
which ftp server is the best? (most secure, easy to administer, etc.)

If this sort of post strikes you as redundant or boring, by all
means...just skip over it :)

--
          a8888b.
         d888888b.
         8P"YP"Y88
         8|o||o|88      Dave Robbins

         8`._,' Y8.
        d/      `8b.
       dP   .    Y8b.
      d8:'  "  `::88b
     d8"         'Y88b
    :8P    '      :888
     88888a:     _a88P
   ._/"Yaa_:   .| 88P|
   \    YP"    `| 8P  `.
   /     \.___.d|    .'
  `--..___)8888P`._.'

-------------

Dave Robbins

-------------

 
 
 

secure ftp

Post by Bill Unr » Sat, 15 Dec 2001 02:50:29


]If anyone out there runs an ftp server, I would appreciate any opinions on
]which ftp server is the best? (most secure, easy to administer, etc.)

All are pretty trivial to administer I think.
I am using vsftpd right now (for about 3 weeks) and it is certainly easy
to set up ( one config file in /etc/vsftp.conf)
My main complaint is the "cute" error messages which the author felt
called upon to include. (make my day, have fun, Sorry dude, ....)
These do not give the impression of a professional piece of work.
(I have made a Mandrake RPM out of this, which fixed some but not all of
these messages. If interested I sent a copy tothe Mandrake contrib
section-- do not know if it has shown up yet though. You could also get
it from ftp://theory.physics.ubc.ca/vsftpd-1.0.1-1mdk*

 
 
 

secure ftp

Post by Bogomip » Thu, 20 Dec 2001 05:42:17


Quote:> If anyone out there runs an ftp server, I would appreciate any opinions on
> which ftp server is the best? (most secure, easy to administer, etc.)

I don't wanna start a battle here. Nevertheless, pure-ftpd is very
interessing and easy for newbie.

A good idea to switch from the proftpd-way-of-ftp  -- www.pureftpd.org

Regards,

Bogomips

 
 
 

secure ftp

Post by WarpKa » Fri, 21 Dec 2001 06:52:07



> If anyone out there runs an ftp server, I would appreciate any opinions
> on which ftp server is the best? (most secure, easy to administer, etc.)

> If this sort of post strikes you as redundant or boring, by all
> means...just skip over it :)

I use ProFTPd across my server platforms.  I don't like the way bugs keep
popping up in WuFTPd.

In addition to it's difficult setup which I found very annoying.

ProFTPd has some pretty kick-ass features like MySQL utilization, but
I've not done anything of the sort yet...not sure if I want to.

--
-----------------------------------------------------------------
 From the Linux Box of WarpKat

 Download my public key from:

   or retrieve it from
  http://www.keyserver.net as WarpKat
                             (Public Key expires 01/04/2002)
-----------------------------------------------------------------

 
 
 

secure ftp

Post by Luke Voge » Fri, 21 Dec 2001 15:19:53




> > If anyone out there runs an ftp server, I would appreciate any opinions
> > on which ftp server is the best? (most secure, easy to administer, etc.)

> > If this sort of post strikes you as redundant or boring, by all
> > means...just skip over it :)

> I use ProFTPd across my server platforms.  I don't like the way bugs keep
> popping up in WuFTPd.

And ProFTPd is bug free ... right?

-----From BUGTRAQ--------


Subject: ProFTPD - Problems in file globbing, gives segmentation fault.
Date: Wed, 19 Dec 2001 14:22:40 +0100
Mime-Version: 1.0
Content-Type: text/plain; format=flowed

SUMMARY
=======
A problem in handling file globbing exists in the current version of
ProFTPD
1.2.4 (but its fixed in the Candidate version: 1.2.5rc1). This
is very similar to the wu-ftpd bug (ls ~{) and occurs when you issue
the command: ls /////////// (11 or more /). I havent figured out if
its exploitable. Thats why I post it to you guys. :-)

AFFECTED VERSIONS
=================
ProFTPD 1.2.4
ProFTPD 1.2.2rc3
(Others may be affected as well.)
-------------------------

--
Regards
Luke
------
Q:  What does FAQ stand for?
A:  We are Frequently Asked this Question, and we have no idea.
------
C.O.L.S FAQ - http://www.linuxsecurity.com/docs/colsfaq.html
------
PLEASE NOTE: Spamgard (tm) installed.

------

 
 
 

secure ftp

Post by grac.. » Sat, 22 Dec 2001 02:15:45


But has anyone been able to reproduce his errors?  From all of the
follow-up posts on bugtraq, I haven't seen any.  (Although I haven't
been monitoring my email all that closely, so I could very well be
wrong).

Cheers,

-Charlie



>And ProFTPd is bug free ... right?

>-----From BUGTRAQ--------


>Subject: ProFTPD - Problems in file globbing, gives segmentation fault.
>Date: Wed, 19 Dec 2001 14:22:40 +0100
>Mime-Version: 1.0
>Content-Type: text/plain; format=flowed

>SUMMARY
>=======
>A problem in handling file globbing exists in the current version of
>ProFTPD
>1.2.4 (but its fixed in the Candidate version: 1.2.5rc1). This
>is very similar to the wu-ftpd bug (ls ~{) and occurs when you issue
>the command: ls /////////// (11 or more /). I havent figured out if
>its exploitable. Thats why I post it to you guys. :-)

>AFFECTED VERSIONS
>=================
>ProFTPD 1.2.4
>ProFTPD 1.2.2rc3
>(Others may be affected as well.)
>-------------------------

>--
>Regards
>Luke
>------
>Q:  What does FAQ stand for?
>A:  We are Frequently Asked this Question, and we have no idea.
>------
>C.O.L.S FAQ - http://www.linuxsecurity.com/docs/colsfaq.html
>------
>PLEASE NOTE: Spamgard (tm) installed.

>------

--
GPG Key fingerprint = 4F36 EC4F 2F2C 5F59 9690  09E5 4C0F 9DB0 8623 53CE
 
 
 

1. Secure ftp, ftp over stunnel og ftp-ssl.

Hi.

I'm looking for a secure way to offer ftp services to my users. Many users
have asked for the ftp-service, but since it will be the only uncryptated
service on my server i have refused to set it up.

Is there any way to use stunnel or any other app to cryptate the
control-connection of the ftp? cryptating data isn't the most important in
this scenario, but i need to make passwords and usernames unavailable in
regards of sniffing etc.

Can someone please help.
A few pointers would be appreciated.

Thanks in advance!

Chris

2. Making room, which dirs/files may "not" be moved from /usr ?

3. use of secure and non secure FTP on the sme server

4. How and where do I setup port redirection

5. secure - non secure ftp on two NIC's

6. Final resting place for xdos03f

7. ftp or secure ftp ?

8. piping transfer log output to MySQL db

9. secure ftp

10. securing ftp users

11. Any secure ftp protocol?

12. Securing FTP...

13. Secure ftp ste how-to