NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
ranko1
Apr 17, 2012Aspirant
Error with PureFTPd 1.0.31 (whocares) & home directory acce
Hi there,
I've found another error that I would like to get some advice on, on how to fix.
I have setup the WhoCares PureFTP 1.0.31 addon and created a virtual user, this virtual user is assigned to an actual user on my NAS.
When the FTP user logs into the server using the virtual user name credentials they get access to the chrooted path (as designed), but then the FTp user logs into the FTP server using the NAS username, they get access to the /c/home/username folder, and from this they can drill back to the root of the NAS server '/' and get full access to everything.
Can this be stopped? i.e. can I only allow the virtual user FTP access but deny all other users access, such as the NAS users?
I've found another error that I would like to get some advice on, on how to fix.
I have setup the WhoCares PureFTP 1.0.31 addon and created a virtual user, this virtual user is assigned to an actual user on my NAS.
When the FTP user logs into the server using the virtual user name credentials they get access to the chrooted path (as designed), but then the FTp user logs into the FTP server using the NAS username, they get access to the /c/home/username folder, and from this they can drill back to the root of the NAS server '/' and get full access to everything.
Can this be stopped? i.e. can I only allow the virtual user FTP access but deny all other users access, such as the NAS users?
1 Reply
Replies have been turned off for this discussion
- Dewdman42VirtuosoI am sure this is a pure-ftpd configuration issue, I need to figure out how also. I'm not at all sure. It seems that if you have a virual user named "foo" and a system user of the same name, then pure-ftpd uses the system user to login, which puts the client in the folder indicated by /etc/passwd, and all the permissions of such.
I too would like to constrain pure-ftpd so that it only allows virtual users, but I don't know how.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!