<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTP Login lockdown? in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455648#M12397</link>
    <description>James, et. al.:&lt;BR /&gt;&lt;BR /&gt;Sorry, in looking at my post I neglected to state that I'm running 10.20 on a K460. I don't think the ftpaccess solution is available to me on the 10.20 platform...is it? (If so, where?)&lt;BR /&gt;&lt;BR /&gt;Thanks for your continued help.</description>
    <pubDate>Thu, 19 Oct 2000 23:28:52 GMT</pubDate>
    <dc:creator>Walter Maul</dc:creator>
    <dc:date>2000-10-19T23:28:52Z</dc:date>
    <item>
      <title>FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455641#M12390</link>
      <description>Hi all! I have a customer who needs to ftp me some files, but I want to minimize the security risk as much as possible.  I have created an account...and made it active home directory the place where I want the files. However, I don't want this customer to be able to view up the directory tree...so how do I limit this?&lt;BR /&gt;&lt;BR /&gt;Any help with this is greatly appreciated.&lt;BR /&gt;</description>
      <pubDate>Thu, 19 Oct 2000 15:08:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455641#M12390</guid>
      <dc:creator>Walter Maul</dc:creator>
      <dc:date>2000-10-19T15:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455642#M12391</link>
      <description>use /usr/bin/rsh as login shell:&lt;BR /&gt;&lt;BR /&gt;           rsh       Restricted version of the POSIX or Bourne shell command&lt;BR /&gt;                     interpreter.  Sets up a login name and execution&lt;BR /&gt;                     environment whose capabilities are more controlled&lt;BR /&gt;                     (restricted) than normal user shells.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 19 Oct 2000 15:41:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455642#M12391</guid>
      <dc:creator>Victor BERRIDGE</dc:creator>
      <dc:date>2000-10-19T15:41:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455643#M12392</link>
      <description>Peter:&lt;BR /&gt;&lt;BR /&gt;Consider ftp security here too:&lt;BR /&gt;&lt;BR /&gt;Setup restricted accoutns in /etc/ftpusers (see: man 4 ftpusers). &lt;BR /&gt;&lt;BR /&gt;Setup /var/adm/inetd.sec hosts and IPAddresses to allow or deny access as you see fit. (see: man 4 inetd.sec).&lt;BR /&gt;&lt;BR /&gt;See also this thread on 'wu-ftpd' in HP 11.x.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://my1.itrc.hp.com/cm/QuestionAnswer/1,1150,0x47f06c96588ad4118fef0090279cd0f9,00.html" target="_blank"&gt;http://my1.itrc.hp.com/cm/QuestionAnswer/1,1150,0x47f06c96588ad4118fef0090279cd0f9,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;...JRF...&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 19 Oct 2000 15:49:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455643#M12392</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2000-10-19T15:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455644#M12393</link>
      <description>Peter:&lt;BR /&gt;&lt;BR /&gt;I would offer that this document, in addition to my previous post, will help you further:  Document #A5651654.&lt;BR /&gt;&lt;BR /&gt;By following the procedure in this document, a user will not have the ability to travel anywhere outsideof his home directory on the system.  Setting up a bogus shell with exit 0 as the contents will cause the connection&lt;BR /&gt;of a user to be immediately terminated if the user attempts to telnet into the system.&lt;BR /&gt;&lt;BR /&gt;Does this help you any better?&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Thu, 19 Oct 2000 16:15:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455644#M12393</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2000-10-19T16:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455645#M12394</link>
      <description>Peter:&lt;BR /&gt;&lt;BR /&gt;Would it not be better for you to fetch it from your Customer's site (and have him worry about security)?  I find its more acceptable to fetch than to have someone poking around your server! my $0.02</description>
      <pubDate>Thu, 19 Oct 2000 16:26:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455645#M12394</guid>
      <dc:creator>Kofi ARTHIABAH</dc:creator>
      <dc:date>2000-10-19T16:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455646#M12395</link>
      <description>Peter:&lt;BR /&gt;&lt;BR /&gt;Kofi makes a great point!  I too feel the same as he does!!!&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Thu, 19 Oct 2000 16:34:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455646#M12395</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2000-10-19T16:34:00Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455647#M12396</link>
      <description>A agree also,&lt;BR /&gt;in fact I use the for such case:&lt;BR /&gt;an account on driveway &lt;BR /&gt;&lt;A href="http://www.driveway.com/" target="_blank"&gt;http://www.driveway.com/&lt;/A&gt;&lt;BR /&gt;Where I deposit the file and share it with who has to pick it up...&lt;BR /&gt;HAve a look at the site, its free&lt;BR /&gt;Yours&lt;BR /&gt;Victor</description>
      <pubDate>Thu, 19 Oct 2000 16:39:39 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455647#M12396</guid>
      <dc:creator>Victor BERRIDGE</dc:creator>
      <dc:date>2000-10-19T16:39:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455648#M12397</link>
      <description>James, et. al.:&lt;BR /&gt;&lt;BR /&gt;Sorry, in looking at my post I neglected to state that I'm running 10.20 on a K460. I don't think the ftpaccess solution is available to me on the 10.20 platform...is it? (If so, where?)&lt;BR /&gt;&lt;BR /&gt;Thanks for your continued help.</description>
      <pubDate>Thu, 19 Oct 2000 23:28:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455648#M12397</guid>
      <dc:creator>Walter Maul</dc:creator>
      <dc:date>2000-10-19T23:28:52Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455649#M12398</link>
      <description>Peter:&lt;BR /&gt;&lt;BR /&gt;I thought I remembered something; searched this forum and found the thread below.  Pay particular note to Brian Fisher's comments.  It appears that what you want will work on 10.20.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://my1.itrc.hp.com/cm/QuestionAnswer/1,1150,0x715168c57f64d4118fee0090279cd0f9,00.html" target="_blank"&gt;http://my1.itrc.hp.com/cm/QuestionAnswer/1,1150,0x715168c57f64d4118fee0090279cd0f9,00.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;...JRF...</description>
      <pubDate>Fri, 20 Oct 2000 00:42:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455649#M12398</guid>
      <dc:creator>James R. Ferguson</dc:creator>
      <dc:date>2000-10-20T00:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455650#M12399</link>
      <description>If you really wish to do things right get a copy of ProFTP .  This UNIX freeware is 1000s of times better for security and configuration.  You can limit upload and downloads, restrict time of day and lock users into a chroot jail.  The users do not even need unix logins which immediately disables other security risks.  The software can be found at &lt;A href="http://www.proftpd.net." target="_blank"&gt;www.proftpd.net.&lt;/A&gt;  We use it for internet ftp access to restrict clients from viewing other clients files.</description>
      <pubDate>Fri, 20 Oct 2000 20:04:06 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455650#M12399</guid>
      <dc:creator>Tim Nelson</dc:creator>
      <dc:date>2000-10-20T20:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: FTP Login lockdown?</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455651#M12400</link>
      <description>Hi,&lt;BR /&gt;Pls try the following set-up&lt;BR /&gt;1&amp;gt; Create a new dummy account&lt;BR /&gt;2&amp;gt; Give /bin/false as a shell to this account&lt;BR /&gt;   This avoids a risk of thst dummy user getting a shell in your environment.&lt;BR /&gt;3&amp;gt; Next is set-up /etc/ftpusers. Add all your users in this file, except the dummy ID that you have created. &lt;BR /&gt;4&amp;gt; Set up /etc/shells file. Put only one line in this file as /bin/false. No other line should be in this file. This adds up to the security of your system.&lt;BR /&gt;Pls revert if any problem. And do  ot forget to award points.&lt;BR /&gt;Regds.....&lt;BR /&gt;Suhas&lt;BR /&gt;</description>
      <pubDate>Sun, 22 Oct 2000 03:33:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/ftp-login-lockdown/m-p/2455651#M12400</guid>
      <dc:creator>Suhas_2</dc:creator>
      <dc:date>2000-10-22T03:33:57Z</dc:date>
    </item>
  </channel>
</rss>

