DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#1 2009-10-11 13:08:30

crs2027
Member
Registered: 2008-10-14
Posts: 46

FTP built-in (Pure-FTPd)

OK here's the issue,

Using the DNS-323 web configuration page I have set up a Group for FTP access and pointed the group to a public folder; lets say /mnt/HD_a2/FTP/.

Any user in the FTP group can log in an see the files and folders inside this public folder.

Using SSH I have made a 'test file' as read-only and changed the user:group to root (chown root:root .... chmod 755)

Logging in to FTP as any of the users within the group can still change and even delete(!) this test file!!

Is it possible to make a read-only file / folder?  Maybe this is a restriction to the FTP service (Pure-FTP) ?

Anyone else tried this or have a different suggestion to try out?

Thanks very much.

Offline

 

#2 2009-10-11 19:49:35

oxygen
Member
Registered: 2008-03-01
Posts: 320
Website

Re: FTP built-in (Pure-FTPd)

if your ftp user owns the directory he can delete files within. you proably want to change the owner/rights of the directory.

Offline

 

#3 2009-10-12 12:15:48

crs2027
Member
Registered: 2008-10-14
Posts: 46

Re: FTP built-in (Pure-FTPd)

ah right I see, I set the folder to 755 (already owned by a different user:group) and that stops file deletion but now the user logged in to FTP can not create any folders or upload files..  I guess I can make a sub-folder with new permissions but do I really have to make another folder for that to be possible?

Thanks for your help

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB