PPCGeeks Forums HTC Arrive HTC HD2 HTC Thunderbolt HTC Touch Pro 2 HTC Evo 4G HTC Evo 3D Samsung Galaxy S II Motorola Droid X Apple iPhone Blackberry
Go Back   PPCGeeks > Windows Mobile > WM HTC Devices > HTC Apache
Register Community Search

Notices


Reply
 
LinkBack Thread Tools Display Modes
  #51 (permalink)  
Old 02-20-2007, 04:54 PM
bigdoofus's Avatar
N00b
Offline
Pocket PC: HTC Touch Pro
Carrier: Sprint
 
Join Date: Dec 2006
Posts: 26
Reputation: 0
bigdoofus is a n00b
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Quote:
Originally Posted by luv2chill
Hi Mike... here's a solution that is fairly easy to implement (it's what xda-dev does with their FTP).

There are two published login accounts for the ftp:

1. The download account. This account has no upload or file/folder modification privileges whatsoever. It is the account used to download only.

2. The upload account. This account only has access to an "Upload" directory off the root--nothing else. It can be used for uploading, folder creation and file system modification inside the "Upload" directory only. It has no access anywhere else.

Mods (or just you, or whomever) can have an individual login that has full permissions on all directories. They would periodically move files from the upload folder into the applicable download folders--where they will be safe from future deletion.

To make it even more secure, when someone uploads something, we can have a thread where they list the file name and the MD5 hash of the file (there are tools for all OSes that easily calculate this for you). If the FTP mod sees that the file in the upload folder matches the posted hash, then the file is safe to move to its permanent place outside of the Upload folder.

Users should think of the upload folder as a "demilitarized zone". There are no protections on anything put into that folder so use extra caution downloading anything from the Upload folder. Once a file has been moved out of there it has been deemed safe.

Anyway, that's my suggestion. We're no where near as big as xda-dev (yet, anyway!) so keeping up with moving uploads should not be too big a job, especially if several users help out with the task.

And I speak as one of the unfortunate souls who downloaded that malware from xda-dev (neither SAV corporate edtition nor Windows Defender caught it--both up to date with definitions). I watched in horror as it deleted most of my OS files. Luckily I had a USB drive hooked up at the time so I was able to copy over all my stuff immediately. Once I rebooted Windows would no longer load up.

Talk about embarassing. I hadn't been hit by a virus in years. And that thing is MALICIOUS with a captial M. I saved a copy of it intending to analyze it one day (I also need to submit it to the major AV vendors).

So I definitely think we need to implement something to keep people from being able to screw with the FTP structure. Having an Upload folder to be the one unprotected area seems like the best compromise to me.
Good point, this would probably be a lot simpler =P (I'm used to setting up multi-user FTP accounts that need the grainular permissions).
Reply With Quote
  #52 (permalink)  
Old 02-20-2007, 07:06 PM
Perasite's Avatar
Retired Staff
Offline
Pocket PC: HTC Touch Pro
Carrier: Sprint
Location: Yuma, AZ
 
Join Date: Sep 2006
Posts: 1,929
Reputation: 2026
Perasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIPPerasite is a VIP
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Don't hate me... I'm a Windows admin. Doing what I suggested is easy there! For Linux, though, are you running your own server or is the FTP hosted? I'm pretty sure the site is hosted, thus the big move recently, but is the FTP hosted as well? I ask because if you have access to the server I'm sure we (I'd help as much as I can) can figure out some FTP server software that would allow this. I'm also sure we'd help as much as possible in setting it up. Do you have any idea how much bandwidth has gone through the FTP? Maybe seperate hosting for that could be the way to go.
__________________
Now with VGA support on all software!

Projects: (PeraStats 1.7) (PeraCount with Clock 1.3) (PeraCount 1.3) (PeraProfiler 1.2) (S2U2Lock 1.1)
Reply With Quote
  #53 (permalink)  
Old 02-21-2007, 12:59 AM
DopeWeasel's Avatar
PPCGeeks Regular
Offline
Pocket PC: HTC HD2 - TMOUS
Carrier: T-Mobile
Location: Dallas, TX
 
Join Date: Feb 2007
Posts: 160
Reputation: 20
DopeWeasel is just getting started
Mentioned: 0 Post(s)
Tagged: 0 Thread(s)
Windows FTP is simple... if I had the bandwidth (or an open site to FXP through), I'd be happy to play host admin.

... I've done it in the past for certain beta IRC groups
Reply With Quote
Reply

  PPCGeeks > Windows Mobile > WM HTC Devices > HTC Apache


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


All times are GMT -4. The time now is 11:10 AM.


Powered by vBulletin® ©2000 - 2024, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.6.0
©2012 - PPCGeeks.com