Networking Forums

Networking Forums > Computer Networking > Linux Networking > [Proftpd] Reject anonymous logins

Reply
Thread Tools Display Modes

[Proftpd] Reject anonymous logins

 
 
becco
Guest
Posts: n/a

 
      01-30-2004, 11:49 AM
Hi, I'm trying to setup the proftpd server to reject anonymous
connections, and allow only users with a valid username/passwd.

I can't figure out why my proftpd.conf doesn't work: authenticated
users AND anonymous users are allowed to login, while I'd like the
anonymous ones to be rejected.

Can anyone help me?

Here is my proftpd.conf:
--------------------------------
# This is a basic ProFTPD configuration file (rename it to
# 'proftpd.conf' for actual use. It establishes a single server
# and a single anonymous login. It assumes that you have a user/group
# "nobody" and "ftp" for normal operation and anon.

ServerName "Animal FTP Server"
#ServerType inetd
Servertype standalone
DeferWelcome off

ShowSymlinks off
MultilineRFC2228 on
DefaultServer on
AllowOverwrite on

TimeoutNoTransfer 600
TimeoutStalled 600
TimeoutIdle 1200

DisplayLogin welcome.msg
DisplayFirstChdir .message
#LsDefaultOptions "-l"

DenyFilter \*.*/

# Uncomment this if you are using NIS or LDAP to retrieve passwords:
#PersistentPasswd off

# Port 21 is the standard FTP port.
Port 21

# To prevent DoS attacks, set the maximum number of child processes
# to 30. If you need to allow more than 30 concurrent connections
# at once, simply increase this value. Note that this ONLY works
# in standalone mode, in inetd mode you should use an inetd server
# that allows you to limit maximum number of processes per service
# (such as xinetd)
MaxInstances 30

# Set the user and group that the server normally runs at.
User proftpd
Group proftpd

# Normally, we want files to be overwriteable.
<Directory /*>
# Umask 022 is a good standard umask to prevent new files and dirs
# (second parm) from being group and world writable.
Umask 022 022

AllowOverwrite on
</Directory>

# here are my improvements
# chroot for all users of the group ftpuser
DefaultRoot ~ ftp

# grant login only for members of the group
<Limit LOGIN>
DenyGroup !ftp
</Limit>

# disable root login and require a valid shell (from /etc/shells)
<Global>
RootLogin off
RequireValidShell on
</Global>

# increase
UseReverseDNS off
IdentLookups off

# Logging formats
LogFormat default "%h %l %u %t \"%r\" %s %b"
LogFormat auth "%v [%P] %h %t \"%r\" %s"
LogFormat write "%h %l %u %t \"%r\" %s %b"


# activate logging

# every login
ExtendedLog /var/log/ftp_auth.log AUTH auth

# file/dir access
ExtendedLog /var/log/ftp_access.log WRITE,READ write

# forr paranoid (big logfiles!)
#ExtendedLog /var/log/ftp_paranoid.log ALL default
-------------------

Thank you for your help

Marcello
 
Reply With Quote
 
 
 
 
becco
Guest
Posts: n/a

 
      01-30-2004, 03:43 PM
XXL PapaBear wrote:

>
> It doesn't show in our description, this could seem to be a very dumb
> question, but did you restart the service after altering your conf file?


Yes, I did!

Thank you
Marcello
 
Reply With Quote
 
XXL PapaBear
Guest
Posts: n/a

 
      01-30-2004, 08:59 PM
On 30 Jan 2004 04:49:30 -0800
(E-Mail Removed) (becco) wrote:

> Hi, I'm trying to setup the proftpd server to reject anonymous
> connections, and allow only users with a valid username/passwd.
>
> I can't figure out why my proftpd.conf doesn't work: authenticated
> users AND anonymous users are allowed to login, while I'd like the
> anonymous ones to be rejected.
>
> Can anyone help me?
>

[snip]
>
> Thank you for your help
>
> Marcello


It doesn't show in our description, this could seem to be a very dumb question, but did you restart the service after altering your conf file?


\\\\||//
------------oooO---PapaBear----Oooo------------

Jesus is alive! I spoke with Him this morning.
 
Reply With Quote
 
Cameron Kerr
Guest
Posts: n/a

 
      01-31-2004, 02:33 AM
becco <(E-Mail Removed)> wrote:
> Hi, I'm trying to setup the proftpd server to reject anonymous
> connections, and allow only users with a valid username/passwd.


Remove the user "ftp" in the file /etc/ftpusers and restart the ftp
service, as this is the file that lists users prohibited from accessing
via FTP, and the user "ftp" is the anonymous/guest user.

--
Cameron Kerr
(E-Mail Removed) : http://nzgeeks.org/cameron/
Empowered by Perl!
 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Anonymous Call Reject Joe Soap Broadband 55 01-17-2007 02:41 PM
ProFTPD Anonymous directive? Vincent Linux Networking 0 12-09-2006 04:26 PM
how to reject dns server? John Almberg Linux Networking 1 11-19-2004 02:16 PM
Anonymous logins windows 2000 server Cath Windows Networking 0 07-05-2004 12:58 AM
REJECT with tcp reset does not work Akop Pogosian Linux Networking 1 11-15-2003 11:34 AM



1 2 3 4 5 6 7 8 9 10 11