[techtalk] FTP server

Raven, serving genmaicha damask0 at yahoo.com
Thu Mar 29 21:26:42 EST 2001

Heya --

Quoth Keith:
> I've been assigned the task of setting up an FTP server at work....
[snip] I was thinking of using wu, but with all of the vulnerabilities 
> that were just released, I'm not that sure about using it.
> Any suggestions FTP programs and/or any tricks and hints would be 
> appreciated.

     My favorite is Pure-FTP.  It's younger than either wu or Pro, but
it has a lot of really nice security features built in.   It's not
vulnerable to the recent filename globbing bug (wu and Pro both are),
you can restrict users' FTP access to only their home directories if
you like, make an exception for one group, or decide that on a per-user
basis.  You can set quotas for anonymous FTP (if you are going to
install that -- I'd recommend not), you can disable FTP access for
particular users (root!), and you can invoke it from just about any
superserver you like.  The documentation that comes with it is very
clear and helpful, and the first time I tried setting it up, it took
only a half-hour from download to serving users.  (That includes
fifteen minutes of reading all the docs.)

     You can get it from SourceForge at
http://sourceforge.net/projects/pureftpd/ -- available in rpm, deb,
.tar.gz, or whatever suits your fancy.

Raven, who loves her FTP server very much

"`A slow sort of country!' said the Queen. `Now, here, you
 see, it takes all the running you can do, to keep in the
 same place. If you want to get somewhere else, you must run
 at least twice as fast as that!'"
 -- the Red Queen, in Lewis Carrol's "Through the Looking Glass"

