Re: sendmail compromised - Somebody help me!

From: Ohmster (notareal_at_emailaddress.com)
Date: 04/27/05


Date: Tue, 26 Apr 2005 23:01:10 GMT

Adam <adam@somewhere.invalid> wrote in
news:jnct61h43nhtdm8l9tkns977dn1jad8kd3@4ax.com:

> Glad I could be of help.

It is very much appreciated.

>
> One thing I forgot to say.
>
> If you can afford getting a router with VPN features, I would recommend
> doing that, putting your server behind it, allow only the bare minimum
> ports for SMPT, POP, HTTP, and any other basic service that you need to
> have connecting to the world, and make sure that ssh, FTP (unless it is
> absolutely necessary) are not accessible unless you are connected
> through VPN.

I do use an FTP server. It has to be accessible for simple, family
members. I run vsftp as both standard FTP for myself with login and
password, and also as anon so that I can give my family members an FTP
URL, directly to the write only incoming directory, and they can click
it. This brings up a blank, white Explorer window on their desktop. Then
the family member will highlight several photos in Explorer and they can
then drag them on top of the empty (Cannot see anything in there, write
only.) Internet Explorer window and let go of the mouse button. Then the
photos will copy over to the anon FTP server and I get pictures to post
on the family web site that way. My mom is over 80 years old and running
a standard FTP client, let alone VPN is pretty much out of the question.
For her and for most of the family. Click on URL, blank Internet Explorer
windows opens, drag the pictures on top of the blank Internet Explorer
window, and let go of the mouse button. Poof, the pictures are here.

>
> Also make sure that most server software, Apache for example are not
> running as a privileged users, and not using the standard nobody:nobody
> user and group, and for all other users, use strong, hard to guess
> usernames and passwords.

Very careful about that, would not want apache or anything else running
privileged. Web server runs as user "apache" and group "apache, neither
of which are privileged.

>
> It is scary how you would find usernames like test with passwords like
> test, password, nothing, secret, new, ...etc.

Yeah really. Thanks for helping out!

-- 
~Ohmster
ohmster at newsguy dot com


Relevant Pages

  • Re: VPN to ISA server, cant FTP through it
    ... filter on the FTP server first. ... what the client IP address might be, but I do know what the server IP ... through a VPN, will they not be encrypted anyway? ... then the Source Network would be the "created" Network that ws created when ...
    (microsoft.public.isa.vpn)
  • Re: SBS FTP service getting slammed.
    ... VPN not an option right now. ... It only took a few hours for them to find my fresh new FTP Server that had ... Deployment Guidelines for ISA Server 2004 Enterprise Edition ...
    (microsoft.public.security)
  • Re: VPN to ISA server, cant FTP through it
    ... FTP connection for that matter. ... through a VPN, will they not be encrypted anyway? ... but have really only been doing simple maintenance on the ISA server, ... Troubleshooting Client Authentication on Access Rules in ISA Server 2004http://download.microsoft.com/download/9/1/8/918ed2d3-71d0-40ed-8e6d- ... ...
    (microsoft.public.isa.vpn)
  • Re: Access files remotely
    ... you can access your files with a VPN. ... could also use FTP or Remote Desktop (= terminal server). ... order to do that I would have to setup an FTP, ...
    (microsoft.public.windows.server.general)
  • IP security setup question
    ... When the server was deliver to us, FTP, ... SMTP and IIS were installed but nothing would work. ... With Internet Explorer, I could not browse any site even html ones. ...
    (microsoft.public.windows.server.setup)