Vesta Control Panel - Forum

Community Forum

Skip to content

Advanced search
  • Quick links
    • Main site
    • Github repo
    • Google Search
  • FAQ
  • Login
  • Register
  • Board index Main Section Web Server
  • Search

Secure bug: ProFTPD every FTP user see / (root) directory

Questions regarding the Web Server
Apache + Nginx, Nginx + PHP5-FPM
Post Reply
  • Print view
Advanced search
4 posts • Page 1 of 1
krzysztofek
Posts: 19
Joined: Fri Jan 09, 2015 2:29 pm

Secure bug: ProFTPD every FTP user see / (root) directory
  • Quote

Post by krzysztofek » Wed Mar 25, 2015 8:16 am

Hello,
I found an issue. I replaced default FTP server with ProFTPD. I done everything like in Vesta online documentation. Now after login with admin account via ftp client (i have only admin account in my vesta) I am logged into / directory of server and I can see /etc and others directories, not as always to /home/admin. Also when I create another FTP account with specified path, it have access to / directory... For me it's very unsecure. Where I can change it? Or back to Vsftpd?
Best regards, Chris.
Top

skurudo
VestaCP Team
Posts: 8099
Joined: Fri Dec 26, 2014 2:23 pm
Contact:
Contact skurudo
Website Facebook Google+ Skype
Twitter

Re: Secure bug: ProFTPD every FTP user see / (root) director
  • Quote

Post by skurudo » Wed Mar 25, 2015 10:15 am

Hello, Chris.
We talked about this before.

viewtopic.php?f=10&t=7231&p=22959&hilit=sftp#p22959
Temporaly fix is disabling SFTP
In file /etc/rssh.conf disable sftp
#allowsftp

then restart ssh
/etc/init.d/ssh restart
Top

krzysztofek
Posts: 19
Joined: Fri Jan 09, 2015 2:29 pm

Re: Secure bug: ProFTPD every FTP user see / (root) director
  • Quote

Post by krzysztofek » Wed Mar 25, 2015 1:52 pm

I done the changes but admin still have access to / directory. Nothing change. How safely back to Vsftpd? Install it and reverse commands from documentations?
Top

skurudo
VestaCP Team
Posts: 8099
Joined: Fri Dec 26, 2014 2:23 pm
Contact:
Contact skurudo
Website Facebook Google+ Skype
Twitter

Re: Secure bug: ProFTPD every FTP user see / (root) director
  • Quote

Post by skurudo » Wed Mar 25, 2015 2:41 pm

krzysztofek wrote:I done the changes but admin still have access to / directory. Nothing change. How safely back to Vsftpd? Install it and reverse commands from documentations?
Yep, it should work.
Top


Post Reply
  • Print view

4 posts • Page 1 of 1

Return to “Web Server”



  • Board index
  • All times are UTC
  • Delete all board cookies
  • The team
Powered by phpBB® Forum Software © phpBB Limited
*Original Author: Brad Veryard
*Updated to 3.2 by MannixMD
 

 

cron

Login  •  Register

I forgot my password