Author Topic: FTP Warning DON'T USE IT  (Read 1834 times)

funbiggin

  • Zen Apprentice
  • *
  • Posts: 1
  • Karma: +0/-0
    • View Profile
FTP Warning DON'T USE IT
« on: June 16, 2012, 06:39:11 pm »
I’ve been trying to get ftp to work on 2.2 and 2.3 and the only way to get it to work is over SSH. That’s fine on its own but you get FULL ACCESS to the whole file system, you can do anything you want. No other settings restrict you in any way. This is completely unacceptable for a system claiming to be a SBS.
So whatever you do NOT USE the ftp services.

vshaulsk

  • Zen Samurai
  • ****
  • Posts: 477
  • Karma: +9/-1
    • View Profile
Re: FTP Warning DON'T USE IT
« Reply #1 on: June 16, 2012, 06:44:35 pm »
I use FTP (not offer SSH)... just the regular port 21 service.

I also have checked the box under the module to restrict users to their home directories.   My clients can not browse anything but their home directories.  I have version 2.2 fully updated and it has worked like this since day one.

Also if uncheck the box to restrict users to their home directories.... they can browse the entire file system, but they can't see any files other then the ones they have access to.  So if they try to view another directory under home or var or anything.... which they do not have specific access to:  It does not display anything.

The only issue I have had with FTP is that I can not get the secure FTP SSL to work..... for some reason I can not get a client like filezilla to connect.

christian

  • Guest
Re: FTP Warning DON'T USE IT
« Reply #2 on: June 16, 2012, 07:30:12 pm »
I’ve been trying to get ftp to work on 2.2 and 2.3 and the only way to get it to work is over SSH.

Very interesting  :o
Could you explain how you get FTP over SSH and what prevents you to get standard FTP service working?
I mean do you face any error message ?

Furthermore, whatever error or problem you face, this is perhaps a bit early to title "DON'T USE IT" unless you're 100% sure there is a security hole somewhere  8), I mean elsewhere than your own personal implementation that may differ from the standard one  ;)
« Last Edit: June 16, 2012, 07:32:07 pm by christian »

Tymanthius

  • Zen Apprentice
  • *
  • Posts: 25
  • Karma: +1/-0
    • View Profile
Re: FTP Warning DON'T USE IT
« Reply #3 on: June 24, 2012, 10:20:55 pm »
Are you using an Admin/root account to ftp in?  B/c of course they get full access.