Hi, I have a SuSE 6.3 server connected to the net. Installed are apache, qmail, courier-imap and proftpd (from the SuSE CDs), everything works fine, I use the Alias directive of proftpd so that users log in with an "virtual" username and a real users password. I am in the process of switching to another internet access, to keep things consistent, I set up a second PC, installed an identic SuSE, copied the user and group filesand the necessary directory structures (with all permissions). So basically I have two identic PCs. On the new PC I cannot connect with the "virtual" user names to proftpd, but - and that absolutely scares me - with *any* user and password combination! That is e.g. I can login through proftpd with the username "qmailq" (the user required for maintaining the queue of qmail) and the matching password, this user has a valid homedir, the shell is set to "/dev/null". It is absolutely not possible to do that on the original PC, I double and triple checked the configurationfiles of both PCs. If there are no further clues I have no other choice but to expect the new system to be compromised. Thanks in advance mike
That is e.g. I can login through proftpd with the username "qmailq" (the user required for maintaining the queue of qmail) and the matching password, this user has a valid homedir, the shell is set to "/dev/null". It is absolutely not possible to do that on the original PC, I double and triple checked the configurationfiles of both PCs.
Sigh. If people only read the documentation. Default is that proftpd wants users to have a "valid" shell, i.e. one listed in /etc/shells. I doubt that /dev/null is listed there (unless you added it, HINT).
If there are no further clues I have no other choice but to expect the new system to be compromised.
Is this access anonymous? I suspect it is, take a chill pill and read the proftd docs and configure your server properly.
Thanks in advance
mike
Kurt Seifried - seifried@securityportal.com SecurityPortal, your focal point for security on the net http://www.securityportal.com/
participants (2)
-
Kurt Seifried
-
Thomas Michael Wanka