Re: XForms: ftp upload : server error

Skip Carter (skip@taygeta.com)
Thu, 22 Jan 1998 19:26:57 -0800

To subscribers of the xforms list from Skip Carter <skip@taygeta.com> :

>T.C. Zhao wrote:

>> all my incoming ftp directories got filled hundreds of
>> megabytes of porn and pirated software a while ago.

>That happened to us too. robots sniff writable directory
>in public fpt sites.

>Two solutions to the problem:

>1) remove all writable directory (e.g. incoming) or make them
>non-writable.

>or

>2) create a "private" directory, not readable and non writable.
>In this directory, create an incomming (writable) directory
>give it a name different from incomming, that only you and
>the other party knows. That's what we do.

Another possibility is to make the incoming directory "write-once-only",
(766 root/wheel) they will still be able to download stuff but no one but
root will be able to read it so there will be little incentive to download
stuff that is not legitimate. After the file arrives, root will have to
change permissions on it and move it to a "public" location.

And of course, you log the transfers and lock out anybody who is being
really troublesome.

That's what we do here.

Skip

Everett (Skip) Carter Phone: 408-641-0645 FAX: 408-641-0647
Taygeta Scientific Inc. INTERNET: skip@taygeta.com
1340 Munras Ave., Suite 314 WWW: /cgi-bin/exit-to?http://www.taygeta.com/
Monterey, CA. 93940

_________________________________________________
To unsubscribe, send the message "unsubscribe" to
xforms-request@bob.usuf2.usuhs.mil or see
http://bob.usuf2.usuhs.mil/mailserv/xforms.html
Xforms Home Page: http://bloch.phys.uwm.edu/xforms
List Archive: http://bob.usuf2.usuhs.mil/mailserv/list-archives/