Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 10 Jun 1998 14:20:28 +0100
From:      Karl Pielorz <kpielorz@tdx.co.uk>
To:        isp@FreeBSD.ORG
Subject:   wu-ftpd problems?
Message-ID:  <357E881C.8061DFA6@tdx.co.uk>

next in thread | raw e-mail | index | archive | help
I'm running wu-ftpd from the ports collection on a 2.2.2 box... (wu-ftpd
version 'wu-2.4.2-academ[BETA-13](1)'.

I've just noticed that the following file:

-rw-r--r--	root	bin	index.html

Can be renamed by someone logging into the ftp server as 'wwwadmin' (group
wwwadmin) - and doing a rename from CuteFTP - they can rename the file to
something like:

-rw-r--r--	root	bin	youstink.html

The directory the file is in is:

-rwxr-xr-x	wwwadmin	bin

Am I doing something funny - is there something I've missed - or is it more
likely to be a misconfigured wu-ftpd?

We've also been looking at switching back to the regular (i.e. ships with
FreeBSD ftpd) - as it will support nice things like internal 'ls' etc...
Anyone got any comments on this?

Regards,

Karl Pielorz

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?357E881C.8061DFA6>