LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices

Reply
 
Search this Thread
Old 12-20-2007, 02:01 AM   #1
rushenas
Member
 
Registered: May 2005
Posts: 34

Rep: Reputation: 15
FTP server with vsftpd


Hi
I read the manual of vsftpd.conf, and it says "If chroot_local_user set to YES, local users will be (by default) placed in a chroot() jail in their home directory after login". I think this means if I enable this directive to Yes, when users connect to my FTP server, they only can access to their home folder.
But the manual warns me "Warning: This option has security implications, especially if the users have upload permission, or shell access. Only enable if you know what you are doing". Why it says so? I permit my users to upload files, but when they are restricted in their home directory, where is the problem?
 
Old 12-20-2007, 03:36 AM   #2
brianmcgee
Member
 
Registered: Jun 2007
Location: Munich, Germany
Distribution: RHEL, CentOS, Fedora, SLES (...)
Posts: 399

Rep: Reputation: 38
Usually you should not trust any uploaded files. Ideally they are chowned to an unpriviledged user account and the uploader should not have any rights to the file once the upload was complete. Only after an administrator evaluated the files, they should be accessible again.

In a home directory the user usually has the right to change the files and to set permissions. For example a user may upload a file and choose to execute the file in his userspace.

If the file is an exploit there is the possibility that the user may escalate their userrights.

For security reasons the upload area of a ftp server should be on a seperate partition. The chrooted users should get access to these areas via bind-mount.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
FTP (vsftpd) and web server (apache) TC10284 Linux - Software 2 07-15-2006 06:14 PM
vsftpd FTP server problems. paquete Slackware 2 10-20-2005 11:38 AM
FTP server help -Vsftpd BinkyFiz Linux - Software 0 02-28-2005 06:56 PM
FTP SERVER: Vsftpd Problems. swatward Linux - Software 2 01-23-2005 09:40 PM
FTP server statistics - vsftpd lazo Linux - Software 0 12-22-2004 09:33 AM


All times are GMT -5. The time now is 12:06 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration