[K12OSN] Anyone provide ftp access to students?

Mike Ely mely at rogueriver.k12.or.us
Thu Mar 2 17:21:26 UTC 2006


Shawn Powers wrote:
> I also provide "webftp" so that they can upload/download files via a 
> webpage as well.  (FTP was too complicated for many of our staff 
> members... don't get me started...)
> 
> I actually *did* have problems with SSH access to the outside, because 
> many kids had guessable passwords.  I had a few accounts compromised, 
> and was running some zombie apps due to the SSH access.  It was a 
> wonderful day.  (note heavy sarcasm)
> 

Agreed.  Sometimes it's better to set something like WebDAV up or simple 
.htaccess auth than to go whole hog - all my normal user accounts have 
their shell variable set to /bin/false, for just the reason Shawn 
expresses above.  Giving the kids shell access is a short trip to hell IMO.

I'd personally avoid FTP for the same reason as ssh - a shell's a shell.

Cheers,
MIke




More information about the K12OSN mailing list