Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 6 Aug 2008 14:15:02 GMT
From:      edwin@FreeBSD.org
To:        root@monolit-r.ru, edwin@FreeBSD.org, freebsd-bugs@FreeBSD.org
Subject:   Re: bin/72508: ftp(1): Anyone can change root on anonymous ftp
Message-ID:  <200808061415.m76EF23w036923@freefall.freebsd.org>

index | next in thread | raw e-mail

Synopsis: ftp(1): Anyone can change root on anonymous ftp

State-Changed-From-To: open->closed
State-Changed-By: edwin
State-Changed-When: Wed Aug 6 14:02:20 UTC 2008
State-Changed-Why: 
This is a so called "don't do this" issue.

> Anyone can change root on anonymous ftp

That is not true. You need administrator access on the FTP server.
You need privileges to make the necessary changes to that file
system.

Don't move directories from unsecure parts of the filesystem to
secure parts of the filesystem.


http://www.freebsd.org/cgi/query-pr.cgi?pr=72508


home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200808061415.m76EF23w036923>