PaulDotCom mailing list archives

Ideas for Securing my FTP Server


From: tkrabec at gmail.com (Tim Krabec)
Date: Sun, 22 Mar 2009 16:51:37 -0400

You might want to look at http://denyhosts.sourceforge.net/  You can choose
how long to blog IP's based on a number of failed logon attempts

2009/3/22 Shaun Curry <shauncurry1 at gmail.com>

Well... I was up til 3am trying to get OpenBSD to work with a GNOME desktop
environment (remember I come from a windows background).  I never got it to
work so I have moved on to Ubuntu.  This should allow me to use daemonshield
and some decent firewall software (maybe firestarter?!).

Also, I found a little something on Milw0rm about an exploit for serv-u ftp
server.

" A vulnerability is caused due to an input validation error when handling
FTP "MKD" requests. This can be exploited to escape the FTP root and create
arbitrary directory on the system via directory traversal attacks using the
"\.." character sequence."

http://www.milw0rm.com/exploits/8211

Thank you very much everyone for all your help!  This has been a lesson I
will never forget.

Shaun

_______________________________________________
Pauldotcom mailing list
Pauldotcom at mail.pauldotcom.com
http://mail.pauldotcom.com/cgi-bin/mailman/listinfo/pauldotcom
Main Web Site: http://pauldotcom.com




-- 
Tim Krabec
Kracomp
772-597-2349
smbminute.com
kracomp.blogspot.com
www.kracomp.com
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20090322/045b36fe/attachment.htm 


Current thread: