LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-12-2007, 09:29 PM   #1
icammy
LQ Newbie
 
Registered: Jan 2007
Posts: 4

Rep: Reputation: 0
VSFTP show the Linux hidden files?


Hi all! This is my first post and I would like to ask a question about the configuration of VSFTP. When I use the SmartFTP to login to my ftp account, it shows all the hidden file e.g. .bashrc, .bash_logout and .bash_profile.
For the security reason, I would like to hide these files up. I have read some of the how-to from the web, most of them mentioned to add the line
hide_file={.ssh,.kde,.bash*,.vi*,.gt*,.em*}
However, it doesn’t work for me.
Could you please help for this issue? Thanks in advance!!

Linux system: FC5
Package: vsftpd-2.0.5-8
FTP client: SmartFTP v2.0.1001
 
Old 01-12-2007, 09:39 PM   #2
rickh
Senior Member
 
Registered: May 2004
Location: Albuquerque, NM USA
Distribution: Debian-Lenny/Sid 32/64 Desktop: Generic AMD64-EVGA 680i Laptop: Generic Intel SIS-AC97
Posts: 4,250

Rep: Reputation: 62
vsftpd is a server. The question of whether hidden files should be shown is a client issue. You should not be offering clients the opportunity to download from (or even see) a directory that includes hidden files.
 
Old 01-12-2007, 09:52 PM   #3
icammy
LQ Newbie
 
Registered: Jan 2007
Posts: 4

Original Poster
Rep: Reputation: 0
Hi Rickh! Thanks for your quick reply! =]
VSFTP default that the ftp account login to their home directory
which includes the hidden files that I have mentioned.
So is that I should change the login directory so that
the user would not have the opportunity to see these files?

Is that the parameter hide_file get a bug that it doesn't work or my incorrect setting?
The purpose of hide_file is supposed to hide the files from the user which I defined.
 
Old 01-12-2007, 10:17 PM   #4
rickh
Senior Member
 
Registered: May 2004
Location: Albuquerque, NM USA
Distribution: Debian-Lenny/Sid 32/64 Desktop: Generic AMD64-EVGA 680i Laptop: Generic Intel SIS-AC97
Posts: 4,250

Rep: Reputation: 62
Quote:
VSFTP default that the ftp account login to their home directory
A user has all the powers of root within his own account. Why shouldn't he be able to see the hidden files?

On Debian, the default vsftpd setup is anonymous users, but they can see only the default directory, /home/ftp/. As root, I can add files to that directory for users to download, but that's the only way anything gets in that directory.

Here is a good article about setting up vsftpd securely.

Last edited by rickh; 01-12-2007 at 10:21 PM.
 
Old 01-12-2007, 11:42 PM   #5
osdeals
Member
 
Registered: Jul 2006
Distribution: RHEL, CentOS, PuppyLinux, SuSe, Ubuntu, Debian
Posts: 59

Rep: Reputation: 15
.bashrc, .bash_logout & .bash_profile are actually files that a shell user might want to modify, since they exist for the explicit purpose of the user customizing what happens when they login / logout.

Revealing them does not really pose a security threat. Especially so if you do not give them shell access. You can remove shell access for the user by changing the shell to /sbin/nologin for the user.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
show hidden files in shell lion_heart_300 Slackware 4 06-29-2006 07:28 AM
ls -->don show hidden files alaios Linux - General 2 07-25-2005 02:19 PM
Show hidden files and folders in Mac OS X Akiva Other *NIX 2 07-22-2005 10:54 PM
show hidden files in ooo 1.1.3 dinges Linux - Newbie 9 02-21-2005 06:51 AM
show hidden files on Redhat 9.0 dflorence Linux - Newbie 3 11-05-2003 11:11 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:41 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration