- Community Home
- >
- Servers and Operating Systems
- >
- Operating Systems
- >
- Operating System - HP-UX
- >
- FTP access only
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Forums
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 12:30 AM
05-10-2004 12:30 AM
A query, if a user has ftp access only (no telnet access) , he can still ftp a .profile file of his own creation to his own directory and then get FULL privileges. That's true is it not ? Any ideas on how to address this security issue.
Thanks & Rgds
Pat
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 12:43 AM - last edited on 09-16-2024 02:19 AM by support_s
05-10-2004 12:43 AM - last edited on 09-16-2024 02:19 AM by support_s
Re: FTP access only
that is possible only if you allow him to ftp it to his/her home directory as well as more than read permission for the .profile file.
however, since telnet is not available by causing an exit everytime the user try to telnet, i am unsure how he/she is able to get FULL prvileges.
regards.
- Tags:
- enclosure
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 01:03 AM
05-10-2004 01:03 AM
Re: FTP access only
Rgds...Geoff
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 01:05 AM
05-10-2004 01:05 AM
Re: FTP access only
A user does not need write access to their .profile
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 04:08 AM
05-10-2004 04:08 AM
SolutionHowever, the comments about making sure .profile is read only or not owned by the user to disallow overwriting it anyway isn't quite accurate, I think. Wouldn't this be the same as users being able to overwrite their .profile in a telnet session? This is controlled by the home directory permissions, not the .profile permissions, right? Unless you want to block people from uploading files to their home directories on the server entirely by doing that, I don't think you can protect the .profile that way.
Jeff Traigle
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 04:14 AM
05-10-2004 04:14 AM
Re: FTP access only
ftp will still work, but they won't be able to login via telnet.
HTH
-- Rod Hills
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 05:31 PM
05-10-2004 05:31 PM
Re: FTP access only
Rgds
Pat
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 06:02 PM
05-10-2004 06:02 PM
Re: FTP access only
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 06:38 PM
05-10-2004 06:38 PM
Re: FTP access only
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 07:30 PM
05-10-2004 07:30 PM
Re: FTP access only
any reason why jeff gets the points and we get none???
regards.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
05-10-2004 07:48 PM
05-10-2004 07:48 PM
Re: FTP access only
Many thanks once again to everyone.
Rgds
Pat