PDA

View Full Version : regarding proftpd and users with shell access


Ovidiu
5th December 2005, 11:03
Hi guys,

using debian 3.1, setup accordingly to the eprfect debian setup and using ispconfig.

I got a report from tiger :

# Checking listening processes
NEW: --WARN-- [lin003w] The process `proftpd' is listening on socket 40492 (TCP on
81.169.176.18 interface) is run by web19_tibi.


now my question is how can a user with shell access (web19_tibi) be the owner of the listening proftpd deamon?
Or is this a normal behaviour?

till
5th December 2005, 11:43
If i remember correctly, proftpd itself is running as root, if someone connects, a child process is spawned, the child access drops priveliges and runs as the user that has connected until the ftp connection ends.

So i think this report is OK.

Ovidiu
5th December 2005, 14:03
ok thx.
I was investigating this as proftpd disconnects after severall seconds due to an glibc error I described in another post here in the forum. I'll try and downgrade the libc6 to another version, hopefully proftpd will work again.