Re: Proftpd updates

Geert Janssens <[email protected]>
Newsgroups gmane.comp.log.logwatch.devel
Organization Kobalt W.I.T.
Message-ID <[email protected]>
Hi,

I am happy to see changes in the proftpd log watch report. I have proftpd 
installed, and the log report I get is not very helpful right now to me. Mind 
you, it's very well possible this is due to a poorly configured proftpd ! I 
didn't have time yet to investigate this in detail.

I do want to inform you though of some additional unrecognized log entries, 
since you are working in this area now: I have proftpd configured with 
mod_ldap, which enables ldap as an authentication backend for proftpd.

With mod_ldap configured I get a lot of unrecognized messages like this:
<domain name> (<ipaddress>[<ipaddress>]) - mod_ldap: pr_ldap_group_lookup(): 
ldap_search_st() failed: No such object
and like this:
<domain name> (<ipaddress>[<ipaddress>]) - mod_ldap: ldap_handle_getgroups(): 
ldap_search_st() failed: No such object

<domainname> is the fully qualified domain name of my LDAP or proftpd server 
(I can't really tell which of the two, because they are on the same server 
for me).
<ipaddress> is the ip address of the ftp client connecting. You can notice it 
appearing twice per log message. I presume the first would be the ip address, 
and the second the reverse resolved dns entry and for some reason the DNS 
resolution is not working.

These two error messages always come together. First the one, immediatly 
followed by the second.

Again, I don't know what should happen with these messages as I don't know why 
they appear yet. My proftpd setup seems to work fine, even with these errors, 
although it's possible the ldap connections fail all the time, and the pam 
fallback takes over each failed ldap attempt. I really can't tell just yet, 
but I did want to let you know about these additional unrecognised log 
messages, just in case they mean something you someone on the list.

Regards,

Geert

On Sunday 25 March 2007 17:51, Mike Tremaine wrote:
> Updates to the proftpd-messages service have been committed to CVS. A
> lot of the changes are based on the patch that James Treworgy sent in
> [so big thanks to him]. It should now work with both "-" and ":" formats
>   which seems to be the difference between syslog and stand alone
> logging. Some simple Bugs got squished [BadShell had the wrong Hash in
> the reporting section.] I've added Notice and Error reports, ignore
> chroot notices, mod_delay and the no such user listings in favor of the
> USER line.
>
> The only log line that I've seen that has not been handled yet is lines
> like
>
> Unable to open password file
> Unable to open group file
>
> Which I suspect are an attack vector from and ANON login trying to
> change privileges. A little more research and I'll figure out how to
> report those.
>
> -Mike
>
>
> _______________________________________________
> Logwatch-Devel mailing list
> [email protected]
> http://www2.list.logwatch.org:81/mailman/listinfo/logwatch-devel

-- 
Kobalt W.I.T.
Web & Information Technology
Brusselsesteenweg 152
1850 Grimbergen

Tel  : +32 479 339 655
Email: [email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.