|
发表于 2002-10-20 21:21:24
|
显示全部楼层
关于proftpd权限问题
我在测试proftpd 1.2.6时,匿名为只读权限,普通用户为读写权限,发现ftp目
录必须开放执行权限普通用户和匿名用户才可以登陆。请问这回不会带来安全问题。
我记得2000下面是不开放执行权限,否则很危险。
我的proftpd.conf的配置如下,敬请指教
# This is a basic ProFTPD configuration file (rename it to
# 'proftpd.conf' for actual use. It establishes a single server
# and a single anonymous login. It assumes that you have a user/group
# "nobody" and "ftp" for normal operation and anon.
ServerName "tsxht's ftp server"
ServerType standalone
DefaultServer on
# Port 21 is the standard FTP port.
Port 21
# Umask 022 is a good standard umask to prevent new dirs and files
# from being group and world writable.
Umask 022
# To prevent DoS attacks, set the maximum number of child processes
# to 30. If you need to allow more than 30 concurrent connections
# at once, simply increase this value. Note that this ONLY works
# in standalone mode, in inetd mode you should use an inetd server
# that allows you to limit maximum number of processes per service
# (such as xinetd)
MaxInstances 30
# Set the user and group that the server normally runs at.
ServerIdent off
RequireValidShell off
User nobody
Group nobody
DefaultRoot /home/ftp/down ftpusers
# Normally, we want files to be overwriteable.
<Directory /*>
AllowOverwrite on
</Directory>
# A basic anonymous configuration, no upload directories.
<Anonymous /home/ftp/down>
RequireValidShell off
User ftp
Group ftp
# We want clients to be able to login with "anonymous" as well as "ftp"
UserAlias anonymous ftp
# Limit the maximum number of anonymous logins
MaxClients 10
# We want 'welcome.msg' displayed at login, and '.message' displayed
# in each newly chdired directory.
DisplayLogin welcome.msg
DisplayFirstChdir .message
# Limit WRITE everywhere in the anonymous chroot
<Limit WRITE>
AllowGroup ftpusers
DenyAll
</Limit>
</Anonymous> |
|