PPCGeeks Forums HTC Arrive HTC HD2 HTC Thunderbolt HTC Touch Pro 2 HTC Evo 4G HTC Evo 3D Samsung Galaxy S II Motorola Droid X Apple iPhone Blackberry
Go Back   PPCGeeks > Windows Mobile > WM HTC Devices > HTC Apache
Register Community Search

Notices


Reply
 
LinkBack Thread Tools Display Modes
  #41 (permalink)  
Old 02-20-2007, 12:20 AM
luv2chill's Avatar
Retired Staff
Offline
Pocket PC: Apache (PPC6700); Titan (Mogul)
Carrier: Sprint
Location: Lawrence, KS
 
Join Date: Nov 2006
Posts: 1,524
Reputation: 143
luv2chill is keeping up the good workluv2chill is keeping up the good work
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Send a message via ICQ to luv2chill Send a message via AIM to luv2chill Send a message via MSN to luv2chill Send a message via Yahoo to luv2chill Send a message via Skype™ to luv2chill
Not to take away from several good points you made Wizzard, but I think you'll find that the "sticking point" is in the distribution of pre-customized ROMs. Even if federal courts have ruled that users may freely customize their own devices I doubt that includes rights of distributing it to other people over the internet.

Again, don't get me wrong, I think it should be legal, I just don't think it is legal (the distribution).
Reply With Quote
  #42 (permalink)  
Old 02-20-2007, 06:33 AM
helmi_c's Avatar
Retired Staff
Offline
Pocket PC: Android
Carrier: Telkomsel
 
Join Date: Jan 2007
Posts: 128
Reputation: 769
helmi_c knows their stuffhelmi_c knows their stuffhelmi_c knows their stuffhelmi_c knows their stuffhelmi_c knows their stuffhelmi_c knows their stuffhelmi_c knows their stuff
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by jamesus
Quote:
Originally Posted by ROBBLDEL
Guy's...

How does this microclunk blow below the belt effect everyone working on the current roms on this website?

Just wondering how much crap I need to download before its no longer there.. hehe
Can't hurt to stock up!
sure their eyes are on this website also, so please if u guys hv anything regardin wm6 and its port planning stuff be more carefull or better say nothing about it....and yes Can't hurt to stock up just like jamesus said...

btw mike I think md5 hash for any file that upload to ppcgeeks ftp soon will be necessary,... if my info was correct... hopes it just a false alarm...

fyi: before xda-dev ftp files is been attack by virus, most of the rom are replaced with a dangerous virus that will delete ur computer files...
Reply With Quote
  #43 (permalink)  
Old 02-20-2007, 12:08 PM
tbhausen's Avatar
PPCGeeks Regular
Offline
Pocket PC: Sprint HTC Touch PRO
Carrier: Sprint
 
Join Date: Jan 2007
Posts: 130
Reputation: 22
tbhausen is just getting started
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Yikes! I'd like to meet that person in a dark alley.

Todd/Indy
Reply With Quote
  #44 (permalink)  
Old 02-20-2007, 01:46 PM
xmind2006's Avatar
Regular 'Geeker
Offline
Pocket PC: Titan
Carrier: Verizon
 
Join Date: Dec 2006
Posts: 255
Reputation: 15
xmind2006 is a n00b
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Speaking of possibly malicious FTP uploads, can't the FTP be set up to allow access to only those with accounts (i.e. a login other than the EZupload)? This would flag the users that would upload either malicious or illegal software. Just a thought as when I had an FTP server set up a couple years ago it was extremely helpful to view the user and file traffic.
Reply With Quote
  #45 (permalink)  
Old 02-20-2007, 03:16 PM
Perasite's Avatar
Retired Staff
Offline
Pocket PC: HTC Touch Pro
Carrier: Sprint
Location: Yuma, AZ
 
Join Date: Sep 2006
Posts: 1,929
Reputation: 2026
Perasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIP
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
I'd agree, couldn't the FTP login be tied to your forum login? Then any changes (malicious or otherwise) could be tracked to who and when. Proper measures to prevent further errors could then be taken.
Anonymous login could be set to allow download only, while it would take forum credentials to upload.
__________________
Now with VGA support on all software!

Projects: (PeraStats 1.7) (PeraCount with Clock 1.3) (PeraCount 1.3) (PeraProfiler 1.2) (S2U2Lock 1.1)
Reply With Quote
  #46 (permalink)  
Old 02-20-2007, 04:18 PM
Wideawake's Avatar
Founder & Owner
Offline
Pocket PC: iPhone XS Max
Carrier: Sprint
Location: Clermont, Florida
 
Join Date: May 2006
Posts: 5,577
Reputation: 4644
Wideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributions
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
Send a message via Skype™ to Wideawake
If anyone knows how please inform me but the only method I've found is this way. See on a linux server only user per folder so we have to use the one login.....Anonymous login costs more and well I dunno. That why I said scan everything u download.
~Mike
__________________
Please read this before posting.



Reply With Quote
  #47 (permalink)  
Old 02-20-2007, 04:23 PM
bigdoofus's Avatar
N00b
Offline
Pocket PC: HTC Touch Pro
Carrier: Sprint
 
Join Date: Dec 2006
Posts: 26
Reputation: 0
bigdoofus is a n00b
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by Wideawake
If anyone knows how please inform me but the only method I've found is this way. See on a linux server only user per folder so we have to use the one login.....Anonymous login costs more and well I dunno. That why I said scan everything u download.
~Mike
You can create subfolders and assign permissions to different users.
Reply With Quote
  #48 (permalink)  
Old 02-20-2007, 04:27 PM
Wideawake's Avatar
Founder & Owner
Offline
Pocket PC: iPhone XS Max
Carrier: Sprint
Location: Clermont, Florida
 
Join Date: May 2006
Posts: 5,577
Reputation: 4644
Wideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributionsWideawake should be added to the payroll for their contributions
Mentioned: 8 Post(s)
Tagged: 0 Thread(s)
Send a message via Skype™ to Wideawake
And just how would I go about doing such a thing....no clue about ftp servers...
Reply With Quote
  #49 (permalink)  
Old 02-20-2007, 04:37 PM
luv2chill's Avatar
Retired Staff
Offline
Pocket PC: Apache (PPC6700); Titan (Mogul)
Carrier: Sprint
Location: Lawrence, KS
 
Join Date: Nov 2006
Posts: 1,524
Reputation: 143
luv2chill is keeping up the good workluv2chill is keeping up the good work
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Send a message via ICQ to luv2chill Send a message via AIM to luv2chill Send a message via MSN to luv2chill Send a message via Yahoo to luv2chill Send a message via Skype™ to luv2chill
Hi Mike... here's a solution that is fairly easy to implement (it's what xda-dev does with their FTP).

There are two published login accounts for the ftp:

1. The download account. This account has no upload or file/folder modification privileges whatsoever. It is the account used to download only.

2. The upload account. This account only has access to an "Upload" directory off the root--nothing else. It can be used for uploading, folder creation and file system modification inside the "Upload" directory only. It has no access anywhere else.

Mods (or just you, or whomever) can have an individual login that has full permissions on all directories. They would periodically move files from the upload folder into the applicable download folders--where they will be safe from future deletion.

To make it even more secure, when someone uploads something, we can have a thread where they list the file name and the MD5 hash of the file (there are tools for all OSes that easily calculate this for you). If the FTP mod sees that the file in the upload folder matches the posted hash, then the file is safe to move to its permanent place outside of the Upload folder.

Users should think of the upload folder as a "demilitarized zone". There are no protections on anything put into that folder so use extra caution downloading anything from the Upload folder. Once a file has been moved out of there it has been deemed safe.

Anyway, that's my suggestion. We're no where near as big as xda-dev (yet, anyway!) so keeping up with moving uploads should not be too big a job, especially if several users help out with the task.

And I speak as one of the unfortunate souls who downloaded that malware from xda-dev (neither SAV corporate edtition nor Windows Defender caught it--both up to date with definitions). I watched in horror as it deleted most of my OS files. Luckily I had a USB drive hooked up at the time so I was able to copy over all my stuff immediately. Once I rebooted Windows would no longer load up.

Talk about embarassing. I hadn't been hit by a virus in years. And that thing is MALICIOUS with a captial M. I saved a copy of it intending to analyze it one day (I also need to submit it to the major AV vendors).

So I definitely think we need to implement something to keep people from being able to screw with the FTP structure. Having an Upload folder to be the one unprotected area seems like the best compromise to me.
Reply With Quote
  #50 (permalink)  
Old 02-20-2007, 04:49 PM
bigdoofus's Avatar
N00b
Offline
Pocket PC: HTC Touch Pro
Carrier: Sprint
 
Join Date: Dec 2006
Posts: 26
Reputation: 0
bigdoofus is a n00b
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by Wideawake
And just how would I go about doing such a thing....no clue about ftp servers...
Assuming you have shell access to the server, you can create a subdirectory such as say, colonel. Then you can create a user named colonel, set his home directory to that directory. Then you can change the permissions to allow only him to write.

I usually use ProFTPd instead of the normal ftp server since it provides much more capabilities in this regard (creating users with write permission, allowing anonymous people to read) without actually create actual users. If you can install it, I can definitely help you set it up.
Reply With Quote
Reply

  PPCGeeks > Windows Mobile > WM HTC Devices > HTC Apache


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -4. The time now is 02:43 AM.


Powered by vBulletin® ©2000 - 2025, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0
©2012 - PPCGeeks.com