Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 23 Dec 2011 12:55:22 -0500
From:      Mike Tancsa <mike@sentex.net>
To:        Stephen Montgomery-Smith <stephen@missouri.edu>
Cc:        freebsd-stable@freebsd.org
Subject:   Re: FLAME - security advisories on the 23rd ? uncool idea is uncool
Message-ID:  <4EF4C08A.3080609@sentex.net>
In-Reply-To: <4EF4B982.3070207@missouri.edu>
References:  <4EF4A75C.2040609@my.gd> <4EF4B2D6.5090206@sentex.net> <4EF4B982.3070207@missouri.edu>

next in thread | previous in thread | raw e-mail | index | archive | help
On 12/23/2011 12:25 PM, Stephen Montgomery-Smith wrote:
> 
> It is this chroot issue that bothers me.  From my reading of the ftpd
> man page, if I have anonymous ftp to my server, it seems that I am using
> chroot with ftpd, and there is no way to stop this happening.
> 
> Am I correct, or have I missed something?  (I am hoping I missed
> something.)

Depends what they can write to and upload. The thread starts here

http://lists.freebsd.org/pipermail/freebsd-security/2011-November/006085.html

that discusses it in more detail

	---Mike



-- 
-------------------
Mike Tancsa, tel +1 519 651 3400
Sentex Communications, mike@sentex.net
Providing Internet services since 1994 www.sentex.net
Cambridge, Ontario Canada   http://www.tancsa.com/



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?4EF4C08A.3080609>