*BSD News Article 84236


Return to BSD News archive

Path: euryale.cc.adfa.oz.au!newshost.carno.net.au!harbinger.cc.monash.edu.au!munnari.OZ.AU!news.Hawaii.Edu!ames!agate!overload.lbl.gov!news.emf.net!news.uoregon.edu!hunter.premier.net!news.mathworks.com!news.sprintlink.net!news-peer.sprintlink.net!news.sprintlink.net!news-hub.sprintlink.net!news.sprintlink.net!news-dc-2.sprintlink.net!coopnews.coop.net!hops.entertain.com!stout.entertain.com!not-for-mail
From: dwatson@stout.entertain.com (Darryl Watson)
Newsgroups: comp.unix.bsd.bsdi.misc
Subject: WU-FTP woes
Date: 4 Dec 1996 18:21:48 -0700
Organization: ABWAM, Inc., full service ISP, voice: 1+ 303 730-6050
Lines: 14
Message-ID: <58583c$a3d@stout.entertain.com>
NNTP-Posting-Host: stout.entertain.com


I've got BSDI 2.0 w/ patches, and am running wu-ftp 2.4.

My system fails (or passes!?) the '200-problem' detailed in the AUSCERT 
ftpd warning text, so I believe my site is vulnerable to criminals 
(unauthorized users).

How can I shut off the SITE EXEC command, or compile the source?  I tried 
compiling, but it poofs on the 3rd or fourth source file.  I even RTFM'd 
the INSTALL and README files, and followed their advice.

Perhaps there is a BSDI patch for this?

Thanks!