Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 10 of 10
  1. #1
    Member
    Join Date
    Nov 2003
    Posts
    521

    Default Disabling root access via Ftp??

    I'm using pureftp and last night someone was trying to access root via ftp, but was unsuccessful. I was told that pureftp doesn't have anything by default that would prevent someone logging in to root.

    So i'm curious.. is this true or not?

  2. #2
    Member
    Join Date
    Mar 2003
    Location
    Dallas, TX
    Posts
    45

    Default

    Add root to /etc/ftpusers.

    Any user listed in this file will not be able to FTP to your server. This is a standard which all FTP servers conform to.

  3. #3
    Member
    Join Date
    Jan 2004
    Posts
    56

    Default On the contrary

    On the contrary I would like to access my server (which is using Pureftp) by logging in as root and also to be able to view the complete directory tree. From beginning on my server it is neither possible to log in as root nor to view the complete directory tree.

  4. #4
    Member
    Join Date
    Mar 2003
    Location
    Dallas, TX
    Posts
    45

    Default

    On the contrary? If you are not able to login as root, then root is probably already in /etc/ftpusers. A few distributions follow this by default, as do some datacenters.

    Of course, this is as it should be. There is absolutely no excuse for logging into FTP or any other service for that matter with root. FTP is especially bad because it transmits passwords in clear text.

  5. #5
    Member webolocity's Avatar
    Join Date
    Jul 2003
    Posts
    82

    Default SSH Program

    If you want a good program which uses SSH and allows for both view of trees (such as in FTP), as well as switching to shell, try this one.

    http://www.ssh.com/

    It is not free. but it works well, and utilizes SSH instead of in-secure FTP.

    Hope this helps.

  6. #6
    Member
    Join Date
    Aug 2003
    Posts
    20

    Default

    What do you do when you have to login as another user first and then SU as root? I cant seem to find an SU option in the program (I've been using it for quite a while..)

  7. #7
    Member
    Join Date
    Jan 2004
    Posts
    56

    Default

    No, root is not in my /etc/ftpusers. I get a Authentication failed in my WS_ftp.

  8. #8
    Member webolocity's Avatar
    Join Date
    Jul 2003
    Posts
    82

    Default Re: ssh.com program

    --------------------------------------------------------------------
    Re: "What do you do when you have to login as another user first and then SU as root? I cant seem to find an SU option in the program (I've been using it for quite a while..)"
    -------------------------------------------------------------------

    We use it to login as root since it uses SSH, and we give no other accounts shell access.

    What I would try is to sign on as the user via the ftp part, and than connect to the shell part using the toggle at the top, su as root, than use the toggle again to go back to the FTP part, and see if it than has you as root.

    I would close out the FTP part, after you have gone to shell, so that it would need to be re-opened when you use the link to get back to that part of the program (after you have used su to root in shell).

    Usually, when you use the icon, after signing into shell you are not required to log in again, so maybe it would not require a re-login to the FTP portion as well.

    Hope that works for you.
    Last edited by webolocity; 01-31-2004 at 01:41 PM.

  9. #9
    Member
    Join Date
    Apr 2004
    Location
    São Paulo - Brasil
    Posts
    22

  10. #10
    Member
    Join Date
    Oct 2002
    Posts
    751

    Default

    I recently switched to Pureftpd, but the /etc/ftpusers file doesn't seem to have any effect with Pureftpd

    When I try to log in with a username listed in /etc/ftpusers I get this message :

    331 User test OK. Password required

    Can someone verify this?

    Other things I noticed:

    - pureftpd doesn't log failed attempts to /var/log/secure (proftpd does)
    - the shell command 'last' doesn't show any users who logged in with ftp
    Last edited by jamesbond; 07-25-2005 at 04:07 PM.

Similar Threads & Tags
Similar threads

  1. Disabling FTP Access
    By Simonson in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 02-20-2010, 02:19 PM
  2. disabling ftp access for an account without disabling account
    By periwinkle in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 10-25-2007, 06:14 PM
  3. root ftp access
    By useradmin in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 10-16-2007, 07:47 AM
  4. Disabling ssh access for root and allowing "su"
    By billau in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 07-17-2004, 04:54 PM
  5. Disabling Anonymous FTP access server wide
    By Domenico in forum cPanel and WHM Discussions
    Replies: 12
    Last Post: 12-01-2001, 05:58 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube