|
|||
|
SFTP/SSH really concerns me! Security!
Im running WS_FTP 8.0.3. I configured it to connect to my own site using SFTP/SSH and i was able to connect to my own site using this however i was really shocked when i clicked on the little green arrow at the top of my screen and moved out of my own webspace. Not only was i able to view the passwrd file but i was able to pretty much see a whole bunch of directories that i think should not be available to anyone using SFTP/SSH.
I was even able to download a copy of the servers password file. The following directories were displayed when i moved out of my own virtual space /bin /dev /etc /home/myhdomain /lib /proc /tmp /usr /var checkvirtfs So this means all my users connecting via SFTP/SSH have been able to see all this? I realize they can see these directories even when jailed but at least they cannot download files from the server. The point being, my account is JAILED yet i can see everthing. Last edited by mr.wonderful; 06-14-2004 at 12:59 AM. |
|
||||
|
Welcome to server security! That's all perfectly normal.
If you couldn't read the passwd file you wouldn't be able to login. Bearing in mind, of course, that your passwords are not stored in the /etc/passwd file. They're in /etc/shadow which should be rw only to root. One option available that helps a little with regard to viewing everyones files in /home is to use /scripts/enablefileprotect
__________________
Jonathan Michaelson cPanel Forum Moderator Need your cPanel servers secured and tuned? cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf http://www.configserver.com |
|
||||
|
Quote:
__________________
Jonathan Michaelson cPanel Forum Moderator Need your cPanel servers secured and tuned? cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf http://www.configserver.com |
|
||||
|
Quote:
__________________
Michael |
|
||||
|
Quote:
The only advantage of FTP over SSL os that your username/password/data is not sent in plain-text. As I said, such implementations are just one security layer which might slow someone down a little, but not much.
__________________
Jonathan Michaelson cPanel Forum Moderator Need your cPanel servers secured and tuned? cPanel Server Configuration, Security, Recovery and Antivirus/AntiSpam Services Developers of the most effective (and free) Firewall & Security Solution for cPanel Servers - csf http://www.configserver.com |
![]() |
| Thread Tools | |
| Display Modes | |
|
|