Ftpfs security hole particulary fixed

Pavel Roskin proski at gnu.org
Thu Jan 31 19:04:34 UTC 2002


Hi, Andrew!

> > I thing that "umask" in the menu is an overkill.
> 
> I want to leave umask question opened.

Ok, my only worry is that MC performs badly on slow FTP servers, so adding 
any other commend means that it will be even slower.  However, MC performs 
better after it stopped calling mc_stat for ".."

Please add the umode command if you insist and nobody in the list objects.

> Well, my wu-ftpd does "LIST -la" absolutely right
> and others understands this as "LIST -lad".  So, if -d option is a
> common place for ftp servers I will commit patch where all of
> occurences of "LIST -la" will be replaced by "LIST -lad"

Good that you found it.  However, I suspect that some servers will only 
print the entry for "." instead of the whole listing.  That's what the 
UNIX command does:

$ ls -ald
drwx------   34 proski   proski       4096 Jan 31 13:54 .

It would be better it you reported the problem with that server.  You
could also test other FTP clients to see it they work with the broken
server (try e.g. gftp and Far Manager).

-- 
Regards,
Pavel Roskin




More information about the mc-devel mailing list