Neil Blakey-Milner on Tue, 5 Sep 2000 10:49:36 +0200


[Date Prev] [Date Next] [Thread Prev] [Thread Next] [Date Index] [Thread Index]

Re: GLUG: Successful Intrusion into my system


On Mon 2000-09-04 (21:01), smitty wrote:
> If he got in through anonymous login for FTP then just about the 
> entire internet is vulnerable almost every site I have ever been to 
> allows anymous login...

Only people who stupidly run wu-ftpd or proftpd or similar need worry.

I think the 'University of Washington' should scare any sane security
person into not using it.

(I'd suggest publicfile by Dan J. Bernstein for anonymous access only,
or FreeBSD (or OpenBSD) ftpd for both anonymous and user access.  Of
course, ftp is as insecure as telnet.  Ick.)

Neil
-- 
Neil Blakey-Milner
Sunesi Clinical Systems
nbm@xxxxxxxxxxxxxxxxxxx