LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-24-2004, 05:51 AM   #1
evasion81
LQ Newbie
 
Registered: Feb 2004
Posts: 9

Rep: Reputation: 0
people connecting to my machine via ftp


hi all,

i have been keeping an eye on my servers log. I see that every now and again a certain ip connects to my machine and tries a few ftp connections using anonymous, test, irc etc. They are getting unknown user errors but is there anything I should do to make sure its safe?

I have a firewall and closed ports I dont use etc. I was thinking of setting up a rule that only allows my ip to use ftp and block everyone else as currently only I use the ftp.

Any thoughts? suggestions? or help?

Thanks!

Stewart
 
Old 02-24-2004, 06:04 AM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Having people probe your FTP server for holes is pretty common. If you're the only one who needs access, then by all means restrict it to only the IPs you need (an iptables rule would work fine). Usually its SOP to restrict access to services to as few systems as you possibly can.
 
Old 02-24-2004, 07:14 AM   #3
evasion81
LQ Newbie
 
Registered: Feb 2004
Posts: 9

Original Poster
Rep: Reputation: 0
Quote:
SOP
What does that mean? thanks again for your reply
 
Old 02-24-2004, 07:22 AM   #4
evasion81
LQ Newbie
 
Registered: Feb 2004
Posts: 9

Original Poster
Rep: Reputation: 0
SOP = standard operating practice?

if so are you saying most ppl restrict to as few as possible

or

do you mean they restrict as much as possible?
 
Old 02-24-2004, 08:00 AM   #5
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
Sorry, SOP=Standard Operating Procedure/Practice

Meaning you should try and give access only to those that need it. If you're the only one you want having FTP access, then restrict access to it, so that only your IP can access it. No sense in having it publicly accessible so that every clown out there can pound away at the FTP daemon if you don't need to. FTP and HTTP servers both seem to attract these kinds of probes, so you'll probably sleep better at night if you don't have to worry about who is doing what to your FTP server.
 
Old 02-26-2004, 01:34 PM   #6
flashingcurser
Member
 
Registered: Jan 2003
Distribution: many win/nix/mac
Posts: 259

Rep: Reputation: 32
To further back up what caveman said, I would also look at your ftp config files to make sure if there are restrications you can add to the server its self. Then take a look at ftpusers, in /etc/ftpusers add every account you can think of except yours.

One alternative to ftp if you are the only one who needs files off of this machine is: scp. A tool that comes with ssh, if you have sshd running anyway you may be able to close the ftp server.


Just some thoughts


 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
trouble connecting with people in AIM to send files. dr_zayus69 Linux - Software 5 12-03-2004 10:16 AM
make sure people can telnet to my linux machine iikent Linux - Newbie 9 01-30-2004 09:35 PM
connecting to another windows machine caesarkim Linux - Networking 7 11-26-2003 12:45 PM
connecting to a Windows machine Mladek Linux - Software 2 07-12-2003 05:08 PM
connecting to a win9x machine MeLassen Linux - Newbie 4 10-01-2001 03:53 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 05:33 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration