LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-10-2005, 02:08 AM   #1
nistelrooy
Member
 
Registered: Oct 2003
Location: Singapore
Distribution: debian
Posts: 162

Rep: Reputation: 30
Looking for advise on WWW/SSH/FTP Lockdown


Hi

A learner here. I'll be running a basic WWW/SSH/FTP system for my family members to upload their own website on this debian box.

Each of them will have a user account:
- user1 (Samuel)
- user2 (Steven)
- user3 (Adeline)
- user4 (a friend of mine, unix guy)
- nistelrooy (root, myself)

I'll be running, FTP, SSH, WWW on this box. However, due to this user4 inclusion, it makes me want to secure my box.

I've already locked down SSH to myself only.

But how do i do FTP lockdown to the users above, and all the new users created infuture will not have a ftp account automatically created.

Secondly, i realise these users accounts i created are able to download the configuration files on the boxes. That includes very sensitive files like, /etc/proftpd.conf, /etc/apache2/*. There will be so many files&folders exposed to my users with this ftp opened. How do i make sure that i've locked down all these sensitive files and they're locked down to their own directory?

Are there any other things i need to see to?

Thanks!
 
Old 10-10-2005, 07:15 PM   #2
anomie
Senior Member
 
Registered: Nov 2004
Location: Texas
Distribution: RHEL, Scientific Linux, Debian, Fedora
Posts: 3,935
Blog Entries: 5

Rep: Reputation: Disabled
There is not a short answer to this question.

There are many things to do to properly harden a Linux system, and each of the services you're running are potential holes. You need to read the documentation for the service and read about the ways to harden it as well.

For example, a quick google for 'debian hardening ftp' returned this as one of the results: http://es.tldp.org/Presentaciones/20...-services.html

Well, that's a start. This is a question of how much time and effort you want to spend vs. how valuable the data on that machine is.
 
Old 10-10-2005, 07:37 PM   #3
ralvez
Member
 
Registered: Oct 2003
Location: Canada
Distribution: ArchLinux && Slackware 10.1
Posts: 298

Rep: Reputation: 30
I guess that a more relevant question is: why use ftp at all?
If you are running ssh you can do file transfers (like you would do with ftp) with scp. It's secure, encrypted (passwords that is) and takes care of your security concerns.

Hope this helps.

Rick
 
Old 10-10-2005, 09:42 PM   #4
primo
Member
 
Registered: Jun 2005
Posts: 542

Rep: Reputation: 34
Yeah, don't use FTP. Use either SFTP or scp. To lock them down to their directories use chroot.
 
Old 10-11-2005, 05:21 AM   #5
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
While I agree scp/sftp are more secure, I can imagine that you would need to run FTP for compatibility or other reasons. If you're bound to use FTP, at least use Vsftpd and not another ftpd. It has a near-perfect track record as far as security is concerned (unlike other ftpd's), is in use with many high volume hosts, is actively maintained, will allow you to use a separate password database and allows you to chroot people to their home etc, etc.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Advise on whether to place Subversion (+ ssh) in the DMZ or LAN? almo Linux - Security 3 08-07-2005 03:26 PM
ProFTPD on Debian: FTP Straight to /var/www chatmasta Debian 4 07-02-2005 05:40 PM
how to setup ftp user's diretory as /var/www/html lzyking Linux - Software 4 02-25-2003 12:58 PM
Allow Users FTP access to /var/www in Red hat 7.2 dsolecki Linux - General 6 02-04-2003 01:12 AM
Squid Proxy for DNS, WWW, & FTP gboutwel Linux - Networking 5 11-11-2002 05:36 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:43 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration