Build vsftp service on Linux system

Source: Internet
Author: User

Experiment


Lab Environment:

Build a Linux server and a win7 system client on the virtual machine.


Experimental requirements:

One, anonymous access to the FTP service, and can upload and download directories and files.

Second, the user verifies access to the FTP service, uploads and downloads directories and files.

Third, use the user_list user list file for user access restrictions.

Four, establish the virtual user's account database, and use virtual user access to FTP upload and download directories and files.

Five, establish a separate configuration file for individual virtual users.

Experimental steps:

One, anonymous access to the FTP service, and can upload and download directories and files.


To install the vsftp service using the RPM method :


650) this.width=650; "src=" Http://s3.51cto.com/wyfs02/M02/59/FC/wKioL1TycSujTi_FAAFeIICfzW0707.jpg "title=" Picture 1.png "alt=" Wkiol1tycsujti_faafeiicfzw0707.jpg "/>


To turn off firewall features:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/59/FC/wKioL1TycxzR4fneAADVPB8NEhM683.jpg "title=" 2.jpg " alt= "Wkiol1tycxzr4fneaadvpb8nehm683.jpg"/>


Turn on the VSFTP service and use anonymous user access to download files:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/59/FC/wKioL1Tyc-TCp_VBAACGCsVa5VU444.jpg "title=" 3.jpg " alt= "Wkiol1tyc-tcp_vbaacgcsva5vu444.jpg"/>


Create a file named text.txt under anonymous user site /var/ftp and have the anonymous user access the download:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5A/00/wKiom1TydXLR5TOVAAC127Gtg-8322.jpg "title=" 4.jpg " alt= "Wkiom1tydxlr5tovaac127gtg-8322.jpg"/>


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/59/FC/wKioL1Tyd7SSmhWmAACsKSl-QwM907.jpg "style=" float: none; "title=" 5.jpg "alt=" Wkiol1tyd7ssmhwmaacsksl-qwm907.jpg "/>


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5A/00/wKiom1TydqXSnW61AAGnf-a_-RA747.jpg "style=" float: none; "title=" 6.jpg "alt=" Wkiom1tydqxsnw61aagnf-a_-ra747.jpg "/>



To upload a file using an anonymous user:


Create a file named FTP on the client:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/00/wKiom1Tyd1jR7IhLAACmYsHEp18976.jpg "title=" 7.jpg " alt= "Wkiom1tyd1jr7ihlaacmyshep18976.jpg"/>


Modify the /vsftpd/vsftpd.conf file


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/59/FC/wKioL1TyejyiX7h1AACXLKxWnVc834.jpg "style=" float: none; "title=" 2.jpg "alt=" Wkiol1tyejyix7h1aacxlkxwnvc834.jpg "/>


Press X to remove the # number before Anon_upload_enable=yes


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5A/00/wKiom1TyeS3hupeWAADnRIogIYc343.jpg "style=" float: none; "title=" 1.jpg "alt=" Wkiom1tyes3hupewaadnriogiyc343.jpg "/>


To upload a file successfully you need to put the/var/ftp/pub subdirectory permissions to the maximum


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/59/FC/wKioL1TyfrbBZ6JwAACel9pgRm8860.jpg "title=" 4.jpg " alt= "Wkiol1tyfrbbz6jwaacel9pgrm8860.jpg"/>


Reload the service and test the anonymous user for uploading the file:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/00/wKiom1Tyej_CR_37AAB4ji4FcAw855.jpg "title=" 3.jpg " alt= "Wkiom1tyej_cr_37aab4ji4fcaw855.jpg"/>


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/59/FC/wKioL1Tyf6GReL2jAACxlmqIs6A526.jpg "title=" 5.jpg " alt= "Wkiol1tyf6grel2jaacxlmqis6a526.jpg"/>



650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/00/wKiom1Tyfp6yc1VKAACOTFsyWHo778.jpg "title=" 6.jpg " alt= "Wkiom1tyfp6yc1vkaacotfsywho778.jpg"/>



Two, user authenticated access FTP services, uploading and downloading directories and files.


To create a user named Zhangsan:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/59/FC/wKioL1TygNGCYI_WAADhPBHtYiI020.jpg "title=" 1.jpg " alt= "Wkiol1tygngcyi_waadhpbhtyii020.jpg"/>


Create a file named Zhangsan and Lisi and upload and download them on the server and client respectively :


Client:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5A/00/wKiom1TygR2SNkEbAAFG0uWope0634.jpg "title=" 2.jpg " alt= "Wkiom1tygr2snkebaafg0uwope0634.jpg"/>



Server:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5A/00/wKiom1TygZHyQgd6AADITRRVRMk125.jpg "title=" 3.jpg " alt= "Wkiom1tygzhyqgd6aaditrrvrmk125.jpg"/>


To upload and download files using the client:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/59/FC/wKioL1TyhJ-zRDUiAADdnvRUGP0105.jpg "title=" 4.jpg " alt= "Wkiol1tyhj-zrduiaaddnvrugp0105.jpg"/>


View servers and clients separately:


Server:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/00/wKiom1TyhBCzIrRQAAC89V6gd4o458.jpg "title=" 5.jpg " alt= "Wkiom1tyhbczirrqaac89v6gd4o458.jpg"/>

Client:



650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/59/FC/wKioL1TyhUWC_7RMAAE5v_cpKNs370.jpg "title=" 6.jpg " alt= "Wkiol1tyhuwc_7rmaae5v_cpkns370.jpg"/>


For security purposes, enable users to access only their own host directories:

To configure the vsftpd.conf configuration file:

Remove the # before chroot_local_user=yes , Wq Save to exit, and reload the service.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5A/00/wKiom1TyhfmD7Jv0AADe3oA489E985.jpg "title=" 1.jpg " alt= "Wkiom1tyhfmd7jv0aade3oa489e985.jpg"/>


Test if a user has access to another directory after signing in to FTP :

Ls View users can only access their own host directory:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/59/FC/wKioL1TyiE_hTQlTAAEjbwBVadQ019.jpg "title=" 2.jpg " alt= "Wkiol1tyie_htqltaaejbwbvadq019.jpg"/>


Third, use user_list user list file for user access restrictions.

View User_list File:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/59/FC/wKioL1TyiTqw69yhAAFFMe0XDT8687.jpg "title=" 3.jpg " alt= "Wkiol1tyitqw69yhaaffme0xdt8687.jpg"/>



The user in the test list file cannot log in to the FTP service:


Append a user Zhangsan and reload the service:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/00/wKiom1TyiWGiURaTAACi-a9nu0k955.jpg "title=" 4.jpg " alt= "Wkiom1tyiwgiurataaci-a9nu0k955.jpg"/>


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/59/FD/wKioL1TyinqRqFiMAACjDjO2FlI155.jpg "title=" 5.jpg " alt= "Wkiol1tyinqrqfimaacjdjo2fli155.jpg"/>


Test User Zhangsan Login FTP


Test result is Login failed:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5A/00/wKiom1TyiorzZZ7UAACjLfjmafs059.jpg "title=" 6.jpg " alt= "Wkiom1tyiorzzz7uaacjlfjmafs059.jpg"/>


Test only users in the User_list file can access the FTP service:

At the end of the vsftpd.conf configuration file , add the Userlist_deny=no,wq save to exit and reload the service:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/59/FD/wKioL1TyjaOTQrr_AADJhb0TsAs704.jpg "title=" 7.jpg " alt= "Wkiol1tyjaotqrr_aadjhb0tsas704.jpg"/>


Verify test results: Users in the list can log in and users who are not listed do not have to log in:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5A/00/wKiom1TyjcrTOsHUAAETecgAX94609.jpg "title=" 1.jpg " alt= "Wkiom1tyjcrtoshuaaetecgax94609.jpg"/>


Four, establish the virtual user's account database, and use virtual user access FTP upload and download directories and files.



First create a list file named VUser, odd-numbered users, even passwords:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/00/wKiom1Tyj6Oh7gwkAABEqMIdrCA308.jpg "title=" 2.jpg " alt= "Wkiom1tyj6oh7gwkaabeqmidrca308.jpg"/>


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/59/FD/wKioL1TykeGh7i8jAAEUpVYYyvc053.jpg "title=" 3.jpg " alt= "Wkiol1tykegh7i8jaaeupvyyyvc053.jpg"/>


For security reasons, file permissions should be set to:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/00/wKiom1TykYvSb1OaAAFc3Ej6OpA819.jpg "title=" 4.jpg " alt= "Wkiom1tykyvsb1oaaafc3ej6opa819.jpg"/>


Create the Virtual user mapping account and create the FTP root directory:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/59/FD/wKioL1Tyk_ayHIwwAAC5_OEuwdY674.jpg "title=" 5.jpg " alt= "wkiol1tyk_ayhiwwaac5_oeuwdy674.jpg"/> User


To establish a PAM authentication file for virtual virtual users:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5A/01/wKiom1TymByjAN_VAACIkbiOths736.jpg "title=" 1.jpg " alt= "Wkiom1tymbyjan_vaacikbioths736.jpg"/>


Establish the virtual user authentication parameters, Wq save exit.

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/59/FD/wKioL1TymRqA76PXAADOxAWatcU090.jpg "title=" 2.jpg " alt= "Wkiol1tymrqa76pxaadoxawatcu090.jpg"/>


Configure the Vsftpd.conf file to add virtual user support, Wq Save exit and reload the service:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/01/wKiom1TymEjTvAfqAAClUZw8ko4280.jpg "title=" 3.jpg " alt= "Wkiom1tymejtvafqaacluzw8ko4280.jpg"/>


To test using a virtual user login:

Create a file named VUser on the client and upload the file. View on the server.


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5A/01/wKiom1TymtqS1Tz8AAFO7suEUHI322.jpg "title=" 4.jpg " alt= "Wkiom1tymtqs1tz8aafo7sueuhi322.jpg"/>


Upload files using the virtual user Lisa login FTP service:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/59/FD/wKioL1TynULRM1SDAADhLYjlZN0141.jpg "title=" 6.jpg " alt= "Wkiol1tynulrm1sdaadhlyjlzn0141.jpg"/>


Viewing on the server, the uploaded file belongs to the owner and the group mapping is the SYSTEM account FTPRoot:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5A/01/wKiom1TynETgUed2AACf3pg7wT8505.jpg "title=" 5.jpg " alt= "Wkiom1tynetgued2aacf3pg7wt8505.jpg"/>


Use virtual user Tom to log in, upload files and view files on the server owner, belong to the group.


Create file as Tom File


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5A/01/wKiom1TypvDShMBHAAGNgUwda8A648.jpg "title=" 1.jpg " alt= "Wkiom1typvdshmbhaagnguwda8a648.jpg"/>




650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/59/FD/wKioL1TyqTLyhdm_AACx3gbLoBY584.jpg "title=" 2.jpg " alt= "Wkiol1tyqtlyhdm_aacx3gbloby584.jpg"/>


Viewing virtual users on the server Tom uploads the same file permissions as 600:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/01/wKiom1TyqDjzs3yvAAC_o4FYsho120.jpg "title=" 3.jpg " alt= "Wkiom1tyqdjzs3yvaac_o4fysho120.jpg"/>


Five, create a separate configuration file for individual virtual users , so that their upload permissions are 644:

Add the user_config_dir Configuration item at the end of the vsftpd.conf file ,


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M01/5A/01/wKiom1TyqtjTHt3_AACyfdhkLW4232.jpg "title=" 4.jpg " alt= "Wkiom1tyqtjtht3_aacyfdhklw4232.jpg"/>


In the /etc/vsftpd directory , Create a directory of Vu_dir and a separate configuration file for virtual user Tom in its directory :

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/59/FD/wKioL1TyrNeA1zOxAACZqtKzy84081.jpg "title=" 5.jpg " alt= "Wkiol1tyrnea1zoxaaczqtkzy84081.jpg"/>


Specifies that Tom user uploads the file as 644and sets the anti-mask to 022:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/5A/01/wKiom1TyrKnCpcrdAABZIEkwpTc505.jpg "title=" 6.jpg " alt= "Wkiom1tyrkncpcrdaabziekwptc505.jpg"/>


the client establishes a file name of 111. TXT and use Tom to log in to upload to view file permissions:

650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/59/FD/wKioL1TyrubzbmouAAG7XEMe9GA905.jpg "title=" 1.jpg " alt= "Wkiol1tyrubzbmouaag7xeme9ga905.jpg"/>


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M02/59/FD/wKioL1Tyr8rAKUrBAACeTTj9gwY364.jpg "title=" 2.jpg " alt= "Wkiol1tyr8rakurbaacettj9gwy364.jpg"/>

Test the file permissions on the server to view Tom uploaded on the result to 644:


650) this.width=650; "src=" http://s3.51cto.com/wyfs02/M00/5A/01/wKiom1Tyr0ugMkRcAACuRgTkkig214.jpg "title=" 3.jpg " alt= "Wkiom1tyr0ugmkrcaacurgtkkig214.jpg"/>


Experiment completed


This article from "Joint efforts, common progress ~ ~" blog, please be sure to keep this source http://9067358.blog.51cto.com/9057358/1616276

Build vsftp service on Linux system

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.