首页 数据库 mysql教程 vsftpd-1.1.3配制实例之一:INTERNET_SITE

vsftpd-1.1.3配制实例之一:INTERNET_SITE

Jun 07, 2016 pm 03:06 PM
internet 实例

This example shows how you might set up a (possibly large) internet facing FTP site. The emphasis will be on security and performance. We will see how by integrating vsftpd with xinetd, we get a powerful combination. Step 1) Set up your xi


  This example shows how you might set up a (possibly large) internet facing
  FTP site.
  The emphasis will be on security and performance.
  We will see how by integrating vsftpd with xinetd, we get a powerful
  combination.
  Step 1) Set up your xinetd configuration file.
  An example xinetd configuration file "vsftpd.xinetd" is supplied.
  To install it:
  cp vsftpd.xinetd /etc/xinetd.d/vsftpd
  Let's look at the important content in this file and see what it does:
  disable = no
  socket_type = stream
  wait = no
  This says that the service is active, and it is using standard TCP sockets.
  user = root
  server = /usr/local/sbin/vsftpd
  The server program /usr/local/sbin/vsftpd is used to handle incoming FTP
  requests, and the program is started as root (vsftpd will of course quickly
  drop as much privilege as possible). NOTE! Make sure that you have the vsftpd
  binary installed in /usr/local/sbin (or change the file path in the xinetd
  file).
  per_source = 5
  instances = 200
  For security, the maximum allowed connections from a single IP address is 5.
  The total maximum concurrent connections is 200.
  no_access = 192.168.1.3
  As an example of how to ban certain sites from connecting, 192.168.1.3 will
  be denied access.
  banner_fail = /etc/vsftpd.busy_banner
  This is the file to display to users if the connection is refused for whatever
  reason (too many users, IP banned).
  Example of how to populate it:
  echo "421 Server busy, please try later." > /etc/vsftpd.busy_banner
  log_on_success += PID HOST DURATION
  log_on_failure += HOST
  This will log the IP address of all connection attempts - successful or not,
  along with the time. If an FTP server is launched for the connection, it's
  process ID and usage duration will be logged too. If you are using RedHat
  like me, this log information will appear in /var/log/secure.
  Step 2) Set up your vsftpd configuration file.
  An example file is supplied. Install it like this:
  cp vsftpd.conf /etc
  Let's example the contents of the file:
  # Access rights
  anonymous_enable=YES
  local_enable=NO
  write_enable=NO
  anon_upload_enable=NO
  anon_mkdir_write_enable=NO
  anon_other_write_enable=NO
  This makes sure the FTP server is in anonymous-only mode and that all write
  and upload permissions are disabled. Note that most of these settings are
  the same as the default values anyway - but where security is concerned, it
  is good to be clear.
  # Security
  anon_world_readable_only=YES
  connect_from_port_20=YES
  hide_ids=YES
  pasv_min_port=50000
  pasv_max_port=60000
  These settings, in order
  - Make sure only world-readable files and directories are served.
  - Originates FTP port connections from a secure port - so users on the FTP
  server cannot try and fake file content.
  - Hide the FTP server user IDs and just display "ftp" in directory listings.
  This is also a performance boost.
  - Set a 50000-60000 port range for passive connections - may enable easier
  firewall setup!
  # Features
  xferlog_enable=YES
  ls_recurse_enable=NO
  ascii_download_enable=NO
  async_abor_enable=YES
  In order,
  - Enables recording of transfer stats to /var/log/vsftpd.log
  - Disables "ls -R", to prevent it being used as a DoS attack. Note - sites
  wanting to be copied via the "mirror" program might need to enable this.
  - Disables downloading in ASCII mode, to prevent it being used as a DoS
  attack (ASCII downloads are CPU heavy).
  - Enables older FTP clients to cancel in-progress transfers.
  # Performance
  one_process_model=YES
  idle_session_timeout=120
  data_connection_timeout=300
  accept_timeout=60
  connect_timeout=60
  anon_max_rate=50000
  In order,
  - Activates a faster "one process per connection" model. Note! To maintain
  security, this feature is only available on systems with capabilities - e.g.
  Linux kernel 2.4.
  - Boots off idle users after 2 minutes.
  - Boots off idle downloads after 5 minutes.
  - Boots off hung passive connects after 1 minute.
  - Boots off hung active connects after 1 minute.
  - Limits a single client to ~50kbytes / sec download speed.
  Step 3) Restart xinetd.
  (on RedHat)
  /etc/rc.d/init.d/xinetd restart
  If you run into problems, check:
  1) Your /etc/xinetd.d directory only has one FTP service.
  vsftpd.conf
  # Access rights
  anonymous_enable=YES
  local_enable=NO
  write_enable=NO
  anon_upload_enable=NO
  anon_mkdir_write_enable=NO
  anon_other_write_enable=NO
  # Security
  anon_world_readable_only=YES
  connect_from_port_20=YES
  hide_ids=YES
  pasv_min_port=50000
  pasv_max_port=60000
  # Features
  xferlog_enable=YES
  ls_recurse_enable=NO
  ascii_download_enable=NO
  async_abor_enable=YES
  # Performance
  one_process_model=YES
  idle_session_timeout=120
  data_connection_timeout=300
  accept_timeout=60
  connect_timeout=60
  anon_max_rate=50000
  vsftpd.xinetd
  # vsftpd is the secure FTP server.
  service ftp
  {
  disable = no
  socket_type = stream
  wait = no
  user = root
  server = /usr/local/sbin/vsftpd
  per_source = 5
  instances = 200
  no_access = 192.168.1.3
  banner_fail = /etc/vsftpd.busy_banner
  log_on_success += PID HOST DURATION
  log_on_failure += HOST
  }
  
  
本站声明
本文内容由网友自发贡献,版权归原作者所有,本站不承担相应法律责任。如您发现有涉嫌抄袭侵权的内容,请联系admin@php.cn

热门文章

仓库:如何复兴队友
3 周前 By 尊渡假赌尊渡假赌尊渡假赌
R.E.P.O.能量晶体解释及其做什么(黄色晶体)
1 周前 By 尊渡假赌尊渡假赌尊渡假赌
Hello Kitty Island冒险:如何获得巨型种子
3 周前 By 尊渡假赌尊渡假赌尊渡假赌

热门文章

仓库:如何复兴队友
3 周前 By 尊渡假赌尊渡假赌尊渡假赌
R.E.P.O.能量晶体解释及其做什么(黄色晶体)
1 周前 By 尊渡假赌尊渡假赌尊渡假赌
Hello Kitty Island冒险:如何获得巨型种子
3 周前 By 尊渡假赌尊渡假赌尊渡假赌

热门文章标签

记事本++7.3.1

记事本++7.3.1

好用且免费的代码编辑器

SublimeText3汉化版

SublimeText3汉化版

中文版,非常好用

禅工作室 13.0.1

禅工作室 13.0.1

功能强大的PHP集成开发环境

Dreamweaver CS6

Dreamweaver CS6

视觉化网页开发工具

SublimeText3 Mac版

SublimeText3 Mac版

神级代码编辑软件(SublimeText3)

什么是公网ip 什么是公网ip Sep 27, 2021 am 10:30 AM

什么是公网ip

Python中的SVM实例 Python中的SVM实例 Jun 11, 2023 pm 08:42 PM

Python中的SVM实例

win11无法上网的问题如何解决?处理win11电脑无法连接到internet的方法指南 win11无法上网的问题如何解决?处理win11电脑无法连接到internet的方法指南 Jan 29, 2024 pm 08:57 PM

win11无法上网的问题如何解决?处理win11电脑无法连接到internet的方法指南

internet的通信协议是什么? internet的通信协议是什么? Dec 24, 2020 pm 02:53 PM

internet的通信协议是什么?

如何在没有 Internet 连接的情况下设置 Windows 11 如何在没有 Internet 连接的情况下设置 Windows 11 Apr 15, 2023 am 10:46 AM

如何在没有 Internet 连接的情况下设置 Windows 11

如何删除临时Internet文件 如何删除临时Internet文件 Dec 06, 2023 am 10:56 AM

如何删除临时Internet文件

Oracle实例数量与数据库性能关系 Oracle实例数量与数据库性能关系 Mar 08, 2024 am 09:27 AM

Oracle实例数量与数据库性能关系

ipv6无internet访问权限是什么意思 ipv6无internet访问权限是什么意思 Feb 20, 2023 am 11:52 AM

ipv6无internet访问权限是什么意思

See all articles