DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#26 2009-03-20 16:54:55

madpenguin
Member
Registered: 2008-12-25
Posts: 77

Re: About FTP and files >4GB

alpha wrote:

Do you mean to allow only limited user to login and then do a su command to act like root ? Am I understand correctly ?

Exactly right. NEVER allow root direct access to ssh. Everyone knows their is a "root" account. Make them have to guess at an unprivileged username. Then, as long as you've done an audit of all system perms, they have to figure out root's password once they get in to do any real damage. That's also why you should change the port number. Everyone knows ssh defaults to port 22. Easy enough to scan ports but make them work for it.

You don't have disable anything to upgrade ssh. Just do a "funpkg -u openssh-5.2p1-1.tgz", do a "ps aux" to find out the pid number of '/ffp/sbin/sshd' and then do a "kill -HUP pidnumber". That will restart sshd without bumping you off your session.

Last edited by madpenguin (2009-03-20 17:05:00)

Offline

 

#27 2009-03-20 17:16:15

madpenguin
Member
Registered: 2008-12-25
Posts: 77

Re: About FTP and files >4GB

On a side note, there are newer upstream versions of lighttpd and libpng as well. If your worried about security, you should keep stuff like that updated. If your using stock ffp libpng, you have these unresolved issues:

http://cve.mitre.org/cgi-bin/cvename.cg … -2008-3964
http://cve.mitre.org/cgi-bin/cvename.cg … -2009-0040

Last edited by madpenguin (2009-03-20 17:20:53)

Offline

 

#28 2009-03-20 19:52:58

alpha
Member
From: Lithuania
Registered: 2008-10-06
Posts: 88

Re: About FTP and files >4GB

Wow.... That lots of nice security tips you gave me smile Thanks !
Now, port number ok wink Everything else will be done maybe tomorrow (have not very much free time).
One more question about security: should I disable network access from DNS GUI ? I mean this access when you can map DNS drive like network drive and use it. Is it security issue or not ? Is it possible to map DNS drive from external ?

Regards,
alpha

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB