Is This Security Hole in Mac Os X Server...??? Or I'm missing something...

Pramod_Mac

Registered
Dear Geeks...

I work in a place where we have around 500 users connected to Macos X panther server.... and we are using panther 10.3 client running on G5/G4's/IMac-G5's/IMac-G4 and 1 to 1.67Ghz PB's...

Here is something I found very scary...
I have downloaded fetch (trial FTP software) and was trying to play with it, I have put on the "remote login" on in the "sharing prefs" and went to other machine and tried to access my Lap top Via Fetch FTP client, using guest access and it did not get connected, but when I flip down to "SFTP" option and said to connect and it got connected via guest access... and the scary part is that I can see my whole HDD in the FTP client folder list.... and tried to Get some files from the root volume and it just got it downloaded on to the other machine.... and keeping my fingers crossed I went to other computer... and created a normal user on the server, and from the client machine launched the FTP "fetch" client and did the same as it did above, and I got almost fainted..... as I could see all the files/folders on the server "root" volume... and I could get all the files folders from the server as a normal user.... then what we did went to server and given "NO ACCESS" to the HDD volume for "Others" and it was normal I said thank GOD....) I could not access via "SFTP now, but other services on the server like "our WEB services started giving problem... I'm I missing something here.... or it is really a security glitch..... we are behind firewall, ours is Intranet under a big network... so attack from outside network, is No No... but internally....????
one last thing we have VLANS and this connection is cutting across VLAns whne checked on the local clients..... can any one throw some light on this issue ASAP.... as it scares us...
Sorry for the the long post..

Thx...
 
I only have Tiger in front of me at this point, but under the FTP service, there is a way to change what authenticated users see. You can change between root, share points and home folders, in general.
 
SFTP does not operate through FTP in any way. It is built on top of SSH and uses that for authentication. Now if you have a guest user set up for ssh yes that is a bad thing. However, I suspect that you are using something like public keys to authenticate with the box. So how can you get in with ssh?
 
lurk said:
SFTP does not operate through FTP in any way. It is built on top of SSH and uses that for authentication. Now if you have a guest user set up for ssh yes that is a bad thing. However, I suspect that you are using something like public keys to authenticate with the box. So how can you get in with ssh?


Yes, I know it works over SSH. Misread part of the back and forth in that question, it appears.
 
This is the part I was particularly responding to.

Pramod_Mac said:
but when I flip down to "SFTP" option and said to connect and it got connected via guest access... and the scary part is that I can see my whole HDD in the FTP client folder list....

The is no guest account and you cannot connect to it via ssh - unless you have created such a thing. I was responding to your initial definition of the problem that just plain does not make sense.

So take deep breath and try to connect again. Are you sure that this is as a guest user and not something else getting you in (like ssh-agent)? Can you create a file as this "guest" user? Who is the owned of the created file?

We can start there.
 
Hi All,

Ouch, Its bad on my part, I have corrected the settings right now.... and its fine, Sorry Guys, I'm new to the Server side.. so you will get lot more of these silly questions in future... please bear with me and solve my problems....

I really appreciate your help....
Thx...
 
"Silly" questions is the best way to learn. There are also some good books on the market that you can use as baselines to help you get up to speed quicker, if you feel lost. :)

Michael
 
You are RIGHT!!!!!
if you are born, knowing everything then life would be awfully boring..

Thx you all Geeks...
Pramod
 
Back
Top