View Full Version : ProFTP Vulnerability
Chris
07-19-2005, 07:23 PM
Heads Up
Evidently there is an "issue" with proftp and cpanel is suggesting switching to PureFTP at this point.
http://forums.cpanel.net/showthread.php?t=41521
Bogdan
07-20-2005, 07:15 AM
Can we have an official advice from a PowerVPS staff?
I am worried about this...
Lorio
07-22-2005, 06:04 PM
Switch to the PureFTP Daemon and make sure that you disable the Anonymous FTP access again.
And btw who uses FTP in 2005? Still too many ;-) Passwords are submitted via plain text. I only use SSH. And make sure to switch the standard port to reduce your logs from all the wannabe hackers which try every user/password combination their dictionary knows.
IgnisOlly
07-31-2005, 07:28 PM
well, if you didn't want to provide ssh, then ftp is the only alternative, n'es pas? and, btw, first post!
Olly
Robert
07-31-2005, 11:40 PM
We've actually been rolling out Pure-ftp by default for a while now on our CPanel VPS servers.
So far only CPanel's developers have been able to replicate the issue. I've not seen it discussed elsewhere at legnth about Proftpd (on they're site or other major security sites).
I personally prefer Pure-ftp because of it's faster speed than Proftpd and it's smaller memory print.
hostsussex
08-14-2005, 05:02 AM
My VPS which was set up on cPanel only last week is using Proftpd, and not Pure. How do I switch?
My VPS which was set up on cPanel only last week is using Proftpd, and not Pure. How do I switch?
Goto root WHM >> Service Configuration >> FTP Configuration >> Switch to pure-ftpd.
charles
08-14-2005, 11:48 AM
Goto root WHM >> Service Configuration >> FTP Configuration >> Switch to pure-ftpd.
You will also need to configure it to use the right ports for passive ftp to match the firewall. You'll need the following added to /etc/pure-ftpd.conf
PassivePortRange 61001 65535
Restart pureftpd after addign this.
I'll look into why you didn't get pureftp by default, because afaik our builds were updated to install pureftpd. Are you sure you didn't change it to proftpd?
hth
charles
vBulletin® v3.8.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.