Great Circle Associates Firewalls
(April 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: UUCP vs. Anonymous FTP
From: Doug Hughes <Doug . Hughes @ Eng . Auburn . EDU>
Date: Wed, 10 Apr 1996 10:08:08 -0500
To: firewalls @ greatcircle . com
In-reply-to: <s16a45af . 037 @ amrcorp . com>

>
>
>Hi,
>
>We are planning to replace UUCP with anonymous
>FTP for transferring files. I would like to get
>information on security issues of anonymous FTP
>and the do's and don't's. What are the benefits
>of this and what is the latest release of
>anonymous FTP that is considered stable and safe
>enough. Any information will be welcome. Thanks!!
>
>
>

We use the anonymous FTP from logdaemon (a tcp_wrappers addition).
It works very well for this. files put in the incoming directory
are set so that they cannot be read by user ftp after they are finished
putting. This makes it impossible for warez junkies to use your site
for exchanging copyrited software (assuming all your other permissions
are set the same). Make sure you follow the permissions guidelines. They
are usually documented pretty well in the ftpd man page.

Of note:
incoming directory owend and writable by FTP (world write is discretionary)
pub directory writable by other (local users) but not by owner (ftp)
other directories owned by root (bin, dev, usr, etc) and not writable


[This message posted to firewalls mailing list. Replies posted to
 mailing list should not be CC'd to me. I will read them on the list]

--
____________________________________________________________________________
Doug Hughes					Engineering Network Services
System/Net Admin  				Auburn University
			doug @
 eng .
 auburn .
 edu
		Pro is to Con as progress is to congress


References:
Indexed By Date Previous: Re: Clarification on Encryption Export Using CKE
From: Ian Johnstone-Bryden <ianj-b @ dial . pipex . com>
Next: signoff firewalls k . krummenacher @ spectraweb . ch
From: Kurt Krummenacher <k . krummenacher @ spectraweb . ch>
Indexed By Thread Previous: UUCP vs. Anonymous FTP
From: Jasjit K Singh <Jasjit_K_Singh @ amrcorp . com>
Next: Re: UUCP vs. Anonymous FTP
From: Tufa Lucian <tufa @ lclsv . sfos . ro>

Google
 
Search Internet Search www.greatcircle.com