[ previous ] [ next ] [ threads ]
 
 From:  Henning Andreseck <AndreseckH at gymszbad dot de>
 To:  m0n0wall at lists dot m0n0 dot ch
 Subject:  Re: [m0n0wall] Problems with proftpd
 Date:  Wed, 13 Dec 2006 16:06:53 +0100
okay, now i triedy lees configuation with my extensions. it looks like:

#
# /etc/proftpd.conf -- This is a basic ProFTPD configuration file.
# To really apply changes reload proftpd after modifications.
#

ServerName   "Siegfried"
ServerType   standalone
DeferWelcome   off

MultilineRFC2228  on
DefaultServer   on
ShowSymlinks   on

TimeoutNoTransfer  600
TimeoutStalled   600
TimeoutIdle   1200

DisplayLogin                    welcome.msg
DisplayFirstChdir               .message
ListOptions                 "-l"

DenyFilter   \*.*/

# Uncomment this if you are using NIS or LDAP to retrieve passwords:
#PersistentPasswd  off

# Uncomment this if you would use TLS module:
#TLSEngine    on

# Uncomment this if you would use quota module:
#Quotas    on

# Uncomment this if you would use ratio module:
#Ratios    on

# Port 21 is the standard FTP port.
Port    21

# To prevent DoS attacks, set the maximum number of child processes
# to 30.  If you need to allow more than 30 concurrent connections
# at once, simply increase this value.  Note that this ONLY works
# in standalone mode, in inetd mode you should use an inetd server
# that allows you to limit maximum number of processes per service
# (such as xinetd)
MaxInstances   30

# Set the user and group that the server normally runs at.
User    nobody
Group    nogroup

# Umask 022 is a good standard umask to prevent new files and dirs
# (second parm) from being group and world writable.
Umask    022  022
# Normally, we want files to be overwriteable.
AllowOverwrite   on

# Delay engine reduces impact of the so-called Timing Attack described in
# http://security.lss.hr/index.php?page=details&ID=LSS-2004-10-02
# It is on by default.
#DelayEngine    off

# A basic anonymous configuration, no upload directories.

# <Anonymous ~ftp>
#   User    ftp
#   Group    nogroup
#   # We want clients to be able to login with "anonymous" as well as "ftp"
#   UserAlias   anonymous ftp
#   # Cosmetic changes, all files belongs to ftp user
#   DirFakeUser on ftp
#   DirFakeGroup on ftp
#
#   RequireValidShell  off
#
#   # Limit the maximum number of anonymous logins
#   MaxClients   10
#
#   # We want 'welcome.msg' displayed at login, and '.message' displayed
#   # in each newly chdired directory.
#   DisplayLogin   welcome.msg
#   DisplayFirstChdir  .message
#
#   # Limit WRITE everywhere in the anonymous chroot
#   <Directory *>
#     <Limit WRITE>
#       DenyAll
#     </Limit>
#   </Directory>
#
#   # Uncomment this if you're brave.
#   # <Directory incoming>
#   #   # Umask 022 is a good standard umask to prevent new files and dirs
#   #   # (second parm) from being group and world writable.
#   #   Umask    022  022
#   #            <Limit READ WRITE>
#   #            DenyAll
#   #            </Limit>
#   #            <Limit STOR>
#   #            AllowAll
#   #            </Limit>
#   # </Directory>
#
# </Anonymous>




   DefaultRoot ~ ftpuser

   # Login nur von Mitgliedern der Gruppe ftpuser erlauben
   <Limit LOGIN>
   DenyGroup !ftpuser
   </Limit>


   <Global>
   RootLogin off
   RequireValidShell on
   </Global>

   # Speed erhoehen
   UseReverseDNS off
   IdentLookups off



   # Logging Formate
   LogFormat default "%h %l %u %t \"%r\" %s %b"
   LogFormat auth "%v [%P] %h %t \"%r\" %s"
   LogFormat write "%h %l %u %t \"%r\" %s %b"

   # Logging aktivieren

    # alle logins
   ExtendedLog /var/log/ftp_auth.log AUTH auth

    # file/dir Zugriff
   ExtendedLog /var/log/ftp_access.log WRITE,READ write


   #ExtendedLog /var/log/ftp_paranoid.log ALL default

but it still doesn't work.


root@garfield:~$ ftp unst.homelinux.com
Connected to unst.homelinux.com.
220 ProFTPD 1.3.0 Server (Siegfried) [::ffff:192.168.17.102]
Name (unst.homelinux.com:xxxxxxx): unst
331 Password required for unst.
Password:
230 User unst logged in.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls
229 Entering Extended Passive Mode (|||32895|)
200 EPRT command successful
425 Unable to build data connection: Invalid argument

what am i making wrong?
thank you

-- 

Henning Andreseck		Tel: 05341/394931
Hirtenweg 115			VOIP: 05341/4029356
38259 Salzgitter 		Fax: 01212-513-076-295
-				Mobil: 0160-26-131-71
ICQ: 343-550-862		URL: http://www.unst.de
MSN: HAndreseck at gmx dot de		E-Mail: AndreseckH at gymszbad dot de
Jabber: henning at jabber dot gymszbad dot de
-
PGP-Key: http://unst.de/Henning_Andreseck.asc