[comp.sys.apollo] Found a bug in 'my'ftpd. Security breach.

wjw@ebh.eb.ele.tue.nl (Willem Jan Withagen) (06/04/91)

                                   
Hi all,

I know that people are using the berkely-ftpd which is patched for
Apollo to give them anonymous ftp. I've added more patches to it.

All these seem to contain a bug. I can't get hold of the original author to 
give him the exact details, but I've been able to reproduce the effects on
another system. As long as ftp-upload is not enabled then 

So I advise people who are using an ftpd derived from the ones described above
to obtain a new version 
	at ftp.eb.ele.tue.nl [131.155.20.25]
        in /pub/apollo/myftpd.tar.v38.Z
                       
Regards,
	Willem Jan.

-- 
Eindhoven University of Technology   DomainName:  wjw@eb.ele.tue.nl    
Digital Systems Group, Room EH 10.10 
P.O. 513                             Tel: +31-40-473401
5600 MB Eindhoven                    The Netherlands