<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic wu-ftpd security problem in Operating System - Linux</title>
    <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005671#M75459</link>
    <description>Dear Sir:&lt;BR /&gt;My company do a security scan.So my Linux has two wu-ftpd warning:&lt;BR /&gt;wu-ftpd site exec format string.&lt;BR /&gt;wu-ftpd site newer denial of service.&lt;BR /&gt;&lt;BR /&gt;the wu-ftpd is 2.4.2rv17-3&lt;BR /&gt;the Linux is redhat 6.0&lt;BR /&gt;Can someone help me to fix this problem.&lt;BR /&gt;Or give me some suggestin ?&lt;BR /&gt;Upgrade wu-ftpd or other solution ?&lt;BR /&gt;thanks&lt;BR /&gt; Jack</description>
    <pubDate>Tue, 24 Jun 2003 11:44:44 GMT</pubDate>
    <dc:creator>jack Hu_1</dc:creator>
    <dc:date>2003-06-24T11:44:44Z</dc:date>
    <item>
      <title>wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005671#M75459</link>
      <description>Dear Sir:&lt;BR /&gt;My company do a security scan.So my Linux has two wu-ftpd warning:&lt;BR /&gt;wu-ftpd site exec format string.&lt;BR /&gt;wu-ftpd site newer denial of service.&lt;BR /&gt;&lt;BR /&gt;the wu-ftpd is 2.4.2rv17-3&lt;BR /&gt;the Linux is redhat 6.0&lt;BR /&gt;Can someone help me to fix this problem.&lt;BR /&gt;Or give me some suggestin ?&lt;BR /&gt;Upgrade wu-ftpd or other solution ?&lt;BR /&gt;thanks&lt;BR /&gt; Jack</description>
      <pubDate>Tue, 24 Jun 2003 11:44:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005671#M75459</guid>
      <dc:creator>jack Hu_1</dc:creator>
      <dc:date>2003-06-24T11:44:44Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005672#M75460</link>
      <description>Hi Jack,&lt;BR /&gt;&lt;BR /&gt;The latest version of wu-ftpd is 2.6.2.  Here is the web site for wu-ftpd:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.wu-ftpd.org/" target="_blank"&gt;http://www.wu-ftpd.org/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I'd suggest upgrading to the latest version and re-running the security scan.&lt;BR /&gt;&lt;BR /&gt;Also, if you can, you might want to upgrade to a newer version of RedHat Linux.  The 6.0 version is pretty old and isn't supported any more.&lt;BR /&gt;&lt;BR /&gt;JP&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Jun 2003 12:29:53 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005672#M75460</guid>
      <dc:creator>John Poff</dc:creator>
      <dc:date>2003-06-24T12:29:53Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005673#M75461</link>
      <description>Your best bet is of course the upgrade of the OS.  There are a ton of security holes in 6.0 that are addressed in subsequent releases.&lt;BR /&gt;&lt;BR /&gt;You can however run the Red Hat Update function built into the current OS and just install the latest rpm for the wu-ftp server.&lt;BR /&gt;&lt;BR /&gt;That will take you to 2.6.2&lt;BR /&gt;&lt;BR /&gt;There is nothing inherently insecure about that server.&lt;BR /&gt;&lt;BR /&gt;Red Hat is using the optional vsftp server on their high volume ftp sites.&lt;BR /&gt;&lt;BR /&gt;If you are picking a new version of Red Hat I would suggest 7.3 because its the last stable release in the 7 series.&lt;BR /&gt;&lt;BR /&gt;9.0 is pretty good but its a .0 release and that always slows me down on using it.  I'm currently upgrading my test environment and have run into some issues.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 24 Jun 2003 13:55:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005673#M75461</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-06-24T13:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005674#M75462</link>
      <description>Dear Sir:&lt;BR /&gt;I think it's a good idea for me to upgrade the new version of Linux.&lt;BR /&gt;But now they will do again to scan the security issue.&lt;BR /&gt;So how can I disable the ftp function first ?&lt;BR /&gt;Then I can do the upgrade of Linux and the ftp function later.&lt;BR /&gt;Or just upgrade the ftp function first ?&lt;BR /&gt;thanks&lt;BR /&gt;  Jack</description>
      <pubDate>Tue, 24 Jun 2003 15:09:49 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005674#M75462</guid>
      <dc:creator>jack Hu_1</dc:creator>
      <dc:date>2003-06-24T15:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005675#M75463</link>
      <description>To disable ftp do as follows:&lt;BR /&gt;&lt;BR /&gt;vi /etc/xinetd.d/wu-ftpd&lt;BR /&gt;&lt;BR /&gt;If should look like this....&lt;BR /&gt;&lt;BR /&gt;# default: on&lt;BR /&gt;# description: The wu-ftpd FTP server serves FTP connections. It uses #       normal, unencrypted usernames and passwords for authentication.&lt;BR /&gt;service ftp&lt;BR /&gt;{&lt;BR /&gt;        disable = no&lt;BR /&gt;        socket_type             = stream&lt;BR /&gt;        wait                    = no&lt;BR /&gt;        user                    = root&lt;BR /&gt;        server                  = /usr/sbin/in.ftpd&lt;BR /&gt;        server_args             = -l -a&lt;BR /&gt;        log_on_success          += DURATION USERID&lt;BR /&gt;        log_on_failure          += USERID&lt;BR /&gt;        nice                    = 10&lt;BR /&gt;}&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;change dispable to yes&lt;BR /&gt;&lt;BR /&gt;service xinetd restart&lt;BR /&gt;&lt;BR /&gt;Now ftp is disabled.&lt;BR /&gt;&lt;BR /&gt;The actual filename may be different on older versions of redhat  maybe xinetd.d is inetd.d things like that.&lt;BR /&gt;&lt;BR /&gt;But you need to change the config file and restart the xinetd or inetd daemon.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Jun 2003 16:34:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005675#M75463</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-06-24T16:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005676#M75464</link>
      <description>Hello!&lt;BR /&gt;&lt;BR /&gt;To improve your security better is to&lt;BR /&gt;remove the wu-ftp and start to use the vsftp&lt;BR /&gt;works also with SSL (secure ftp)&lt;BR /&gt;RH also remove the wu-ftp and start distribute the vsftp because it's more secure and easy to use.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Caesar</description>
      <pubDate>Tue, 24 Jun 2003 18:28:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005676#M75464</guid>
      <dc:creator>Caesar_3</dc:creator>
      <dc:date>2003-06-24T18:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005677#M75465</link>
      <description>I have used wu-ftpd for years and vsftp for a few months.&lt;BR /&gt;&lt;BR /&gt;Bill Hassell will tell you that wu-ftpd is just as secure as any ftp release out there.  You can stay with it if you are comfortable with it.&lt;BR /&gt;&lt;BR /&gt;vsftp does have some advantages.  Security is not one of them.  It was a write from scratch so there is no support for certain legacy functionality that you may have come to expect in wu-ftpd.  The primary advantage and reason that Red Hat uses it for its external ftp servers is that it handles heavy loads very well.&lt;BR /&gt;&lt;BR /&gt;The vulnerbility in wu-ftpd you originated your post on was discovered and corrected years ago.  I am not seeing frequent security bullitens on this product.  It is old, safe and secure.  &lt;BR /&gt;&lt;BR /&gt;A good idea to track these issues is to subscribe to HP's security bulletins, which cover this product and other common products like sendmail.  You can also subscribe to the CERT security newsletter which will get you updates on common utilities.&lt;BR /&gt;&lt;BR /&gt;The bottom line is nothing is totally secure and you need to be aware of things.&lt;BR /&gt;&lt;BR /&gt;I would recommend one extra thing for any Linux or HP-UX server you admin.  Bastille.  This tool will let you harden the security of either OS with confidence and a simple question and answer interface.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Wed, 25 Jun 2003 00:32:15 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005677#M75465</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2003-06-25T00:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005678#M75466</link>
      <description>The most secure solution you can use is OpenSSH's sftp as all the data is encrypted whilst in transit. You can also take advantage of scp, remote commands etc. OpenSSH is rapidly becoming the standard for secure administration across most platforms.&lt;BR /&gt;&lt;BR /&gt;It also has the advantage that it is free and there is tons of support available for it. If you also want to use secure login (ssh) instead of telnet, I recommend that you download Putty from(&lt;A href="http://www.chiark.greenend.org.uk/~sgtatham/putty/)" target="_blank"&gt;www.chiark.greenend.org.uk/~sgtatham/putty/)&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Putty is an excellent terminal emulator and its also free.&lt;BR /&gt;</description>
      <pubDate>Wed, 25 Jun 2003 05:20:51 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005678#M75466</guid>
      <dc:creator>Andrew Cowan</dc:creator>
      <dc:date>2003-06-25T05:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005679#M75467</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;I concur with John. &lt;BR /&gt;&lt;BR /&gt;Every application has security bugs which the authors missed but found out by other people.&lt;BR /&gt;&lt;BR /&gt;And the authors correct the security bugs in their previous release code with a latest release code.&lt;BR /&gt;&lt;BR /&gt;So I recommend you to download the latest wu-ftpd and install in your machine.&lt;BR /&gt;&lt;BR /&gt;regards,&lt;BR /&gt;&lt;BR /&gt;U.SivaKumar&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 25 Jun 2003 06:00:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005679#M75467</guid>
      <dc:creator>U.SivaKumar_2</dc:creator>
      <dc:date>2003-06-25T06:00:44Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005680#M75468</link>
      <description>Hello!&lt;BR /&gt;&lt;BR /&gt;About the vsftp, ofcourse it's nor secure ftp&lt;BR /&gt;in the way of encript the chanel and all the&lt;BR /&gt;connection, i mean for the security of allow&lt;BR /&gt;users is better made and easy to use.&lt;BR /&gt;&lt;BR /&gt;For the secure chanel ftp should use sftp.&lt;BR /&gt;&lt;BR /&gt;Caesar</description>
      <pubDate>Wed, 25 Jun 2003 18:13:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005680#M75468</guid>
      <dc:creator>Caesar_3</dc:creator>
      <dc:date>2003-06-25T18:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005681#M75469</link>
      <description>Adding to friends advice, and paraphrasing a bit, it depends mainly on who'll conect to your ftp server.&lt;BR /&gt;If it's an inner company ftp server, then wu-ftpd will do the job, as said before, as long as you upgrade to a new version, in which no bug is found yet.&lt;BR /&gt;&lt;BR /&gt;Your sca, looking like nmap or nessus, may warn again, on the risk linked to ftp server, but you just have to quota upload directory to be safe.&lt;BR /&gt;&lt;BR /&gt;wu-ftpd have many good configurations examples :&lt;BR /&gt;&lt;A href="http://www.wu-ftpd.org/HOWTO/" target="_blank"&gt;http://www.wu-ftpd.org/HOWTO/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;vsftpd is knwon as sure, use it if your ftp server is connected outside. I also like very muc pro-ftpd, as its configuration file looks like apache a lot, which is friendly, and is also considered as pretty sure :&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://proftpd.linux.co.uk/" target="_blank"&gt;http://proftpd.linux.co.uk/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;hth&lt;BR /&gt;&lt;BR /&gt;J</description>
      <pubDate>Wed, 25 Jun 2003 18:45:25 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005681#M75469</guid>
      <dc:creator>Jerome Henry</dc:creator>
      <dc:date>2003-06-25T18:45:25Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005682#M75470</link>
      <description>I don't believe RH 6.0 has xinetd.  &lt;BR /&gt;&lt;BR /&gt;To disable ftpd, you can either remove the entry from /etc/inetd.conf, or add the following line to /etc/hosts.deny:&lt;BR /&gt;&lt;BR /&gt;in.ftpd: ALL&lt;BR /&gt;&lt;BR /&gt;This will prevent anyone from logging in via ftp.</description>
      <pubDate>Thu, 26 Jun 2003 02:13:40 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005682#M75470</guid>
      <dc:creator>Bill Douglass</dc:creator>
      <dc:date>2003-06-26T02:13:40Z</dc:date>
    </item>
    <item>
      <title>Re: wu-ftpd security problem</title>
      <link>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005683#M75471</link>
      <description>Dear Sir:&lt;BR /&gt;I first update wu-ftpd to 2.6 version.&lt;BR /&gt;I could the scan now.&lt;BR /&gt;And I will try to upgrade my OS too.&lt;BR /&gt;Also the SSH,.....&lt;BR /&gt;Very thanks for all your help.&lt;BR /&gt;  Jack &lt;BR /&gt;</description>
      <pubDate>Thu, 26 Jun 2003 11:11:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-linux/wu-ftpd-security-problem/m-p/3005683#M75471</guid>
      <dc:creator>jack Hu_1</dc:creator>
      <dc:date>2003-06-26T11:11:14Z</dc:date>
    </item>
  </channel>
</rss>

