How to secure File Transfer server FTP

Source: Internet
Author: User
Tags anonymous ftp access

As an FTP server on the Internet, the security of the system is very important, and this is the first question that is considered by the establishment of the FTP server. Its security mainly includes the following several aspects:

An unauthorized user disables FTP operations on the server.

Second, FTP users cannot read files or directories that are not allowed by the system owner.

Third, without permission, FTP users can not establish files or directories on the server.

Iv. FTP users cannot delete files or directories on the server.

The FTP server has taken some identification of the user to solve the above first problem, mainly including the following measures:

The user account used by the FTP user must be documented in the/etc/passwd file (except for anonymous FTP users), and his password cannot be empty. The server denies access without correctly entering the user account and password.

The FTP Daemon FTPD also uses a/etc/ftpusers file in which users who appear in this file will be denied FTP service by the server. Server management can create an "unwelcome" User directory and Deny access to these users.

The server can accept anonymous FTP connections only if a user named "FTP" exists in the server's/etc/passwd file, and anonymous FTP users can use "anonymous" or "FTP" as their username and their Internet e-mail address as a secret word. To address the other three of the above security issues, the file attributes under the FTP home directory should be managed, and it is recommended that the following measures be taken for each directory and its files:

FTP home directory: Set the owner of this directory to "FTP", and set the property to all users are not writable to prevent malicious users from pruning files.

Ftp/bin directory: This directory mainly places some system files, you should set the owner of this directory to "root" (that is, Superuser), and set the property to all users are not writable. To ensure that legitimate users can display files, the ls file attribute in the directory should be set to executable.

FTP/ETC Directory: Set the owner of this directory to "root" and set the property to all users are not writable. Set the properties of the group file and the passwd file in the directory to all user-read-only properties, and use the editor to delete the password that was added to the user in the passwd file. please contact the site, timely note your name. Contact Email: edu#chinaz.com (change # to @).



Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.