ftpd Security

From: Brian Rowan <brianr_at_tiger.hsc.edu>
Date: Mon, 23 Sep 1996 09:54:48 -0400

Greetings OSFers.....

Recently my /usr/local partition balloned from 52 percent to 97 percent
overnight. While investigating the problem I found a directory in my ftp
structure name "..." so the directory ls -l looked something like this.....

drwxr-xr-x 2 ftp archive 512 Aug 13 13:31 .
drwxr-xr-x 2 ftp archive 512 Aug 13 13:31 ..
drwxr-xr-x 2 ftp archive 512 Aug 13 13:31 ...
<other Directories>

underneath that directory was a complicated structure of other
directories.......
Someone had found a security whole in the ftpd daemon..... I reread the man
page on setting the daemon up and everything looks okay.

So first: Beware of these directories.... I have also found recently
directories under the ftp structure where the name is spaces. so you have
to enclose the spaces in quotes to get to them. aren't users clever.

Second does anyone know of a whole in the ftpd that comes with DU3.0?

Thanks in advance

------------------------------------------------------------------------------
Brian Rowan
Systems Analyst
Hampden-Sydney College
Hampden-Sydney, VA 23943
(804) 223-6208
brianr_at_lion.hsc.edu
------------------------------------------------------------------------------
Received on Mon Sep 23 1996 - 16:23:38 NZST

This archive was generated by hypermail 2.4.0 : Wed Nov 08 2023 - 11:53:47 NZDT