Hello Denys,

I've studied the last patch you applied to ftpd.

The patch can be fixed if you reorder the "change_identity" to beneath the 
jail. 

Also the "change_identity" ought to conflict with the NOMMU jail break. However 
a carefully placed call to "getpwuid" seems to somehow solve this. (wtf?) I've 
tested it on Ubuntu + uClinux. 

An unrelated small issue: The ftpd is not listing hidden files like other ftp 
servers do. This' got to an error? (Solution is simple.)

I've attached a patch with the above.

Regards,
Morten Kvistgaard

> -----Original Message-----
> From: Denys Vlasenko [mailto:[email protected]]
> Sent: 5. august 2014 22:00
> To: Morten Kvistgaard
> Cc: [email protected]
> Subject: Re: ftpd authentication
> 
> On Mon, Aug 4, 2014 at 12:38 PM, Morten Kvistgaard <MK@pch-
> engineering.dk> wrote:
> > I've attached a patch for adding basic authentication to the ftpd.
> >
> > This used to work with version 1.21.1. And walter harms tested it with
> 1.22.1. And it worked with trunk 3 months ago.
> >
> > It doesn't seem to work with the current trunk though?
> >
> > The difference lies with "getpwnam" I think. (It's returning NULL on
> > my Ubuntu.)
> 
> getpwnam will not be very happy in chroot.
> 
> I fixed that, and also added actual change of user identity, and refactored
> password check to not duplicate code.
> 
> Applied to git, please try it now.
> For example, I'm curious whether people who want _anon_ ftp are unhappy
> now....

 
 
--
This message has been scanned for viruses and dangerous content by CronLab
(www.cronlab.com), and is believed to be clean.

Attachment: 0001-fix-ftp-authentication-change_identity-ls-A.patch
Description: 0001-fix-ftp-authentication-change_identity-ls-A.patch

_______________________________________________
busybox mailing list
[email protected]
http://lists.busybox.net/mailman/listinfo/busybox

Reply via email to