Koozali.org: home of the SME Server

Where is it safe to change ftp root to

pbearne

Where is it safe to change ftp root to
« on: December 03, 2004, 05:00:46 PM »
Hi

OK i see that with chroot I can change the ftp root folder

So if I change the root to /mnt/bigdisk will this break all the ibays?

so do I have to change where I mount the hard drive?

or if I chroot to the root / will it work ?

Offline Reinhold

  • *
  • 517
  • +0/-0
    • http://127.0.0.1
Where is it safe to change ftp root to
« Reply #1 on: December 03, 2004, 05:43:24 PM »
Paul,

:-o Getting dangerous now :-o

If you change root for ftp (chroot) to "/" and publish your open ftp url...
:evil: I am sure someone will erase everything on your server as an "educational measure" or so ... within hours :-(

Install a chroot contrib ... like the one from dungog http://www.dungog.net/sme/files/dungog-proftpd-chroot-0.1-5.noarch.rpm
Use the panel to "chroot" the users to the directories they should start (&stay) in.  
They will be allowed to go lower into the specified tree but NOT HIGHER (climb directory tree)
(Example: They may go from /home/mine/ to /home/mine/incoming/ but not to /home/.
...like I said chroot them to the safe (?!) directories on your new big hd ...
/bigdisk/homes/paul and /bigdisk/homes/mary ... or for trusted users /bigdisk/homes ... /bigdisk/incoming

NOBODY should have access to the system parts of your SME via ftp !!!
CHECK this locally (iow before you open ftp up to the world in your admin panel !!!).

You may want to read man chroot  or info chroot or the proftp manual page url I gave you.

If nobody has told you yet in experienced here it is...
Running a ftp server open to the world is among the most unsafe things you can do on SME !!!

Regards
Reinhold
............

pbearne

If I could get vpn to work I would use that
« Reply #2 on: December 03, 2004, 06:00:37 PM »
If I could get vpn to work I would use that

But I just can't get to work :cry:

And when I could use a network share  :lol: