LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-14-2004, 10:05 AM   #1
DigitalSmash
LQ Newbie
 
Registered: Mar 2004
Posts: 17

Rep: Reputation: 0
root ftp consequences


I wouldn't login to ftp as root (or even try for that matter), and I also know most machines wouldn't let you even if you tried without changing default ftp settings.

One of my colleagues recently tried to connect to one of our production servers over ftp as root. I've tried searching for this but everywhere just says "don't do it", but I'm asking why? And what should I do to make sure nothing has been compromised?

I'm newbie(ish) to security- I think I know what not to do however don't know what to do after a machine is compromise or what tools to run etc.

Thanks in advance,
Dave
 
Old 12-14-2004, 10:32 AM   #2
TruckStuff
Member
 
Registered: Apr 2002
Posts: 498

Rep: Reputation: 30
Re: root ftp consequences

Quote:
Originally posted by DigitalSmash
One of my colleagues recently tried to connect to one of our production servers over ftp as root. I've tried searching for this but everywhere just says "don't do it", but I'm asking why? And what should I do to make sure nothing has been compromised?
The FTP protocol sends everything over non-encrypted channels, including user names and passwords. This means that the passwords can be sniffed from the network with remarkable ease. If you FTP as root, you are sending your root password in plain text over the net. If someone sniffs the password, your entire server is compromised .
 
Old 12-14-2004, 10:37 AM   #3
DigitalSmash
LQ Newbie
 
Registered: Mar 2004
Posts: 17

Original Poster
Rep: Reputation: 0
Thanks for the quick reply.

How does one sniff the password? Is that something you'd have to do there and then monitoring a switch or something?
 
Old 12-14-2004, 04:19 PM   #4
phatbastard
Member
 
Registered: Mar 2004
Location: Houston, Texas
Distribution: Kubuntu, zenwalk
Posts: 117

Rep: Reputation: 15
There are plenty of ways to sniff for passwords..... one that comes to mind is a IRC botnet...
 
Old 12-14-2004, 04:45 PM   #5
Mara
Moderator
 
Registered: Feb 2002
Location: Grenoble
Distribution: Debian
Posts: 9,696

Rep: Reputation: 232Reputation: 232Reputation: 232
If the attacker is in the same network only sniffer program (ethreal or similar) is needed. It's very easy to to, so never send plaintext passwords.
 
Old 12-15-2004, 03:24 AM   #6
DigitalSmash
LQ Newbie
 
Registered: Mar 2004
Posts: 17

Original Poster
Rep: Reputation: 0
Thanks all. I guess this is the time I should start reading a network security book!!
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Software RAID: consequences of linux autodetect & persistent-superblock with reiserfs cbonar Linux - Hardware 0 01-08-2005 03:43 PM
Turning off the PnP for SIOCSIFFLAGS error hack... Consequences? SparceMatrix Linux - Hardware 0 09-05-2004 11:02 AM
ftp + root Morg666 Linux - Security 7 04-20-2004 05:19 PM
ftp as root lenlutz Red Hat 3 02-18-2004 04:08 PM
Deleting GNOME.. the consequences Stephanie Linux - General 3 01-28-2002 01:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:42 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration