Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
vsftpd e chroot
View unanswered posts
View posts from last 24 hours
View posts from last 7 days

 
Reply to topic    Gentoo Forums Forum Index Forum italiano (Italian)
View previous topic :: View next topic  
Author Message
bashroot
Tux's lil' helper
Tux's lil' helper


Joined: 01 Feb 2006
Posts: 90
Location: Ferrara

PostPosted: Mon Feb 20, 2006 12:27 am    Post subject: vsftpd e chroot Reply with quote

ciao ragazzuoli stavo configurando il suddetto server , tutto ok a parte che anche avendo inserito nel file di configurazione

Code:
# You may specify an explicit list of local users to chroot() to their home
# directory. If chroot_local_user is YES, then this list becomes a list of
# users to NOT chroot().
chroot_local_user=YES
ls_recurse_enable=NO
#chroot_list_enable=NO
# (default follows)
#chroot_list_file=/etc/vsftpd/chroot_list


gli utenti autenticati non sono chrootati mentre dovrebberlo esserlo , il problema e che mi servirebbe poter far accedere solo persone a cui creo io un account e che siano chrootate nella loro home e non possano andare in giro.
_________________
There is no like try 127.0.0.1
la musica che ascolto http://www.last.fm/user/bashroot/
Back to top
View user's profile Send private message
.:chrome:.
Advocate
Advocate


Joined: 19 Feb 2005
Posts: 4588
Location: Brescia, Italy

PostPosted: Mon Feb 20, 2006 8:19 am    Post subject: Re: vsftpd e chroot Reply with quote

perché non usi questa direttiva?

Code:
#chroot_list_file=/etc/vsftpd/chroot_list
Back to top
View user's profile Send private message
bashroot
Tux's lil' helper
Tux's lil' helper


Joined: 01 Feb 2006
Posts: 90
Location: Ferrara

PostPosted: Mon Feb 20, 2006 9:17 am    Post subject: Reply with quote

perchè dal manuale di vsftpd dice che se abilitata la voce chroot_local_user quelli inseriti in quella lista sono gli utenti non chrootati.
_________________
There is no like try 127.0.0.1
la musica che ascolto http://www.last.fm/user/bashroot/
Back to top
View user's profile Send private message
.:chrome:.
Advocate
Advocate


Joined: 19 Feb 2005
Posts: 4588
Location: Brescia, Italy

PostPosted: Mon Feb 20, 2006 10:36 am    Post subject: Reply with quote

bashroot wrote:
perchè dal manuale di vsftpd dice che se abilitata la voce chroot_local_user quelli inseriti in quella lista sono gli utenti non chrootati.

d'altronde se NON usi chroot_local_user, la direttiva chroot_list_file specifica un elenco di utenti che devono essere posti in chroot
Back to top
View user's profile Send private message
bashroot
Tux's lil' helper
Tux's lil' helper


Joined: 01 Feb 2006
Posts: 90
Location: Ferrara

PostPosted: Mon Feb 20, 2006 10:37 am    Post subject: Reply with quote

allora ho appena provato , da locale il chroot funziona , dall esterno nò
_________________
There is no like try 127.0.0.1
la musica che ascolto http://www.last.fm/user/bashroot/
Back to top
View user's profile Send private message
.:chrome:.
Advocate
Advocate


Joined: 19 Feb 2005
Posts: 4588
Location: Brescia, Italy

PostPosted: Mon Feb 20, 2006 10:52 am    Post subject: Reply with quote

bashroot wrote:
allora ho appena provato , da locale il chroot funziona , dall esterno nò

cosa cosa cosa??? è strano
com'è possibile che da una aprte funzioni e dall'altra no? :(
Back to top
View user's profile Send private message
bashroot
Tux's lil' helper
Tux's lil' helper


Joined: 01 Feb 2006
Posts: 90
Location: Ferrara

PostPosted: Mon Feb 20, 2006 10:55 am    Post subject: Reply with quote

eh lo so ma ho provato con piu persone se mi collego dalla macchina dove ho il server ftp se do per esempio cd / vedo solo la home dell utente con cui mi sono cellegato al ftp ma se lo faccio fare a miei amici dall esterno della mia rete e per esempio danno cd /etc , vedono i file , quindi escono dal chroot.
_________________
There is no like try 127.0.0.1
la musica che ascolto http://www.last.fm/user/bashroot/
Back to top
View user's profile Send private message
bashroot
Tux's lil' helper
Tux's lil' helper


Joined: 01 Feb 2006
Posts: 90
Location: Ferrara

PostPosted: Mon Feb 20, 2006 10:58 am    Post subject: Reply with quote

ti posto il file di conf

Code:

#
# Enable vsftpd to run as a standalone daemon
# Comment these two out to run under inetd or xinetd
background=YES
listen=YES

# Allow anonymous FTP?
anonymous_enable=NO

# Uncomment this to allow local users to log in.
local_enable=YES

# Uncomment this to enable any form of FTP write command.
#write_enable=YES

# Default umask for local users is 077. You may wish to change this to 022,
# if your users expect that (022 is used by most other ftpd's)
local_umask=022                 
anon_umask=0777                 
file_open_mode=0777             
# Uncomment this to allow the anonymous FTP user to upload files. This only
# has an effect if the above global write enable is activated. Also, you will
# obviously need to create a directory writable by the FTP user.
#anon_upload_enable=YES         
                               
# Uncomment this if you want the anonymous FTP user to be able to create
# new directories.             
#anon_mkdir_write_enable=YES   
                               
# Activate directory messages - messages given to remote users when they
# go into a certain directory. 
dirmessage_enable=YES           
                               
# Make sure PORT transfer connections originate from port 20 (ftp-data).
connect_from_port_20=YES       
                               
# If you want, you can arrange for uploaded anonymous files to be owned by
# a different user. Note! Using "root" for uploaded files is not
# recommended!                 
#chown_uploads=YES             
#chown_username=whoever         
                               
# Activate logging of uploads/downloads.
xferlog_enable=YES

# If you want, you can have your log file in standard ftpd xferlog format
#xferlog_std_format=YES

# You may override where the log file goes if you like.
xferlog_file=/var/log/vsftpd.log

# You may change the default value for timing out an idle session.
idle_session_timeout=600

# You may change the default value for timing out a data connection.
#data_connection_timeout=120

# It is recommended that you define on your system a unique user which the
# ftp server can use as a totally isolated and unprivileged user.
nopriv_user=nobody

# Enable this and the server will recognise asynchronous ABOR requests. Not
# recommended for security (the code is non-trivial). Not enabling it,
# however, may confuse older FTP clients.
#async_abor_enable=YES

# By default the server will pretend to allow ASCII mode but in fact ignore
# the request. Turn on the below options to have the server actually do ASCII
# mangling on files when in ASCII mode.
# Beware that turning on ascii_download_enable enables malicious remote parties
# to consume your I/O resources, by issuing the command "SIZE /big/file" in
# ASCII mode.
# These ASCII options are split into upload and download because you may wish
# to enable ASCII uploads (to prevent uploaded scripts etc. from breaking),
# without the DoS risk of SIZE and ASCII downloads. ASCII mangling should be
# on the client anyway..
#ascii_upload_enable=YES
#ascii_download_enable=YES

# You may fully customise the login banner string:
ftpd_banner=Welcome to Nightwish FTP service.

# You may specify a file of disallowed anonymous e-mail addresses. Apparently
# useful for combatting certain DoS attacks.
#deny_email_enable=YES
# (default follows)
#banned_email_file=/etc/vsftpd/banned_emails

# You may specify an explicit list of local users to chroot() to their home
# directory. If chroot_local_user is YES, then this list becomes a list of
# users to NOT chroot().
chroot_local_user=YES
ls_recurse_enable=NO
chroot_list_enable=YES
# (default follows)
chroot_list_file=/etc/vsftpd/chroot_list

# You may activate the "-R" option to the builtin ls. This is disabled by
# default to avoid remote users being able to cause excessive I/O on large
# sites. However, some broken FTP clients such as "ncftp" and "mirror" assume
# the presence of the "-R" option, so there is a strong case for enabling it.
#ls_recurse_enable=YES
max_per_ip=2


lasciando il file etc/vsftpd/chroot_list vuoto come dice il commento.
_________________
There is no like try 127.0.0.1
la musica che ascolto http://www.last.fm/user/bashroot/
Back to top
View user's profile Send private message
ProT-0-TypE
Veteran
Veteran


Joined: 20 Dec 2003
Posts: 1624
Location: Cagliari

PostPosted: Mon Feb 20, 2006 12:35 pm    Post subject: Reply with quote

ma non hai settato secure_chroot_dir?
_________________
[Vuoi guadagnare navigando?]
Back to top
View user's profile Send private message
bashroot
Tux's lil' helper
Tux's lil' helper


Joined: 01 Feb 2006
Posts: 90
Location: Ferrara

PostPosted: Mon Feb 20, 2006 12:54 pm    Post subject: Reply with quote

ProT-0-TypE wrote:
ma non hai settato secure_chroot_dir?


uhm mi sa di no
_________________
There is no like try 127.0.0.1
la musica che ascolto http://www.last.fm/user/bashroot/
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Forum italiano (Italian) All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum