Debian Bug report logs - #574924
RFP: oftpd -- a lightweight anonymous ftpd server daemon

Package: wnpp; Maintainer for wnpp is wnpp@debian.org;

Reported by: markhobley@yahoo.co.uk

Date: Mon, 22 Mar 2010 08:06:01 UTC

Severity: wishlist

Reply or subscribe to this bug.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, wnpp@debian.org:
Bug#574924; Package wnpp. (Mon, 22 Mar 2010 08:06:04 GMT) Full text and rfc822 format available.

Acknowledgement sent to markhobley@yahoo.co.uk:
New Bug report received and forwarded. Copy sent to wnpp@debian.org. (Mon, 22 Mar 2010 08:06:04 GMT) Full text and rfc822 format available.

Message #5 received at submit@bugs.debian.org (full text, mbox):

From: markhobley@yahoo.co.uk
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: RFP: oftpd -- A lightweight anonymous ftpd server daemon
Date: Mon, 22 Mar 2010 08:02:42 +0000
Package: wnpp
Severity: wishlist

* Package name    : oftpd
  Version         : 0.3.7
  Upstream Author : Shane Kerr <shane@time-travellers.org>
* URL             : http://www.time-travellers.org/oftpd/
* License         : GPL
  Programming Lang: C
  Description     : A lightweight anonymous ftpd server daemon

The oftpd server daemon is designed to be as secure as it can possibly be.
It runs as a non root user for most of the time, and uses the Unix chroot()
command to hide most of the systems directories from external users preventing
them from accessing the system directories even if the server is totally
compromised! 

-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (60, 'testing'), (50, 'unstable')
Architecture: i386 (3686)





Changed Bug title to 'ITP: oftpd -- lightweight anonymous FTP server' from 'RFP: oftpd -- A lightweight anonymous ftpd server daemon' Request was from Mats Erik Andersson <mats.andersson@gisladisker.se> to control@bugs.debian.org. (Thu, 01 Apr 2010 08:21:03 GMT) Full text and rfc822 format available.

Owner recorded as Mats Erik Andersson <mats.andersson@gisladisker.se>. Request was from Mats Erik Andersson <mats.andersson@gisladisker.se> to control@bugs.debian.org. (Thu, 01 Apr 2010 08:21:03 GMT) Full text and rfc822 format available.

Information forwarded to debian-bugs-dist@lists.debian.org, wnpp@debian.org, Mats Erik Andersson <mats.andersson@gisladisker.se>:
Bug#574924; Package wnpp. (Fri, 02 Apr 2010 01:12:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to Simon McVittie <smcv@debian.org>:
Extra info received and forwarded to list. Copy sent to wnpp@debian.org, Mats Erik Andersson <mats.andersson@gisladisker.se>. (Fri, 02 Apr 2010 01:12:03 GMT) Full text and rfc822 format available.

Message #14 received at 574924@bugs.debian.org (full text, mbox):

From: Simon McVittie <smcv@debian.org>
To: markhobley@yahoo.co.uk, 574924@bugs.debian.org, Mats Erik Andersson <mats.andersson@gisladisker.se>
Subject: Re: Bug#574924: RFP: oftpd -- A lightweight anonymous ftpd server daemon
Date: Fri, 2 Apr 2010 02:00:13 +0100
[Message part 1 (text/plain, inline)]
Note that oftpd was removed from Debian nearly 5 years ago (Bug #332186), a
year and a half after the last release mentioned on
<http://www.time-travellers.org/oftpd/>. It doesn't seem to have changed
since. Please don't upload this to Debian unless you're willing to take over
upstream development and security support.

In the removal request, Matthew Danish wrote:
> Remove oftpd from unstable.  It has no active upstream maintainer, has a
> couple of outstanding security flaws, and I have no time to attempt to
> fix this myself.
(<http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=332186>)

On Mon, 22 Mar 2010 at 08:02:42 +0000, markhobley@yahoo.co.uk wrote:
> The oftpd server daemon is designed to be as secure as it can possibly be.

The same is frequently said of many ftp servers, as far as I can see...
whether they're *actually* secure is a different matter! vsftpd might be a
good alternative?

Regards,
    Simon
[signature.asc (application/pgp-signature, inline)]

Information forwarded to debian-bugs-dist@lists.debian.org, wnpp@debian.org:
Bug#574924; Package wnpp. (Fri, 02 Apr 2010 17:42:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to Mats Erik Andersson <mats.andersson@gisladisker.se>:
Extra info received and forwarded to list. Copy sent to wnpp@debian.org. (Fri, 02 Apr 2010 17:42:03 GMT) Full text and rfc822 format available.

Message #19 received at 574924@bugs.debian.org (full text, mbox):

From: Mats Erik Andersson <mats.andersson@gisladisker.se>
To: Simon McVittie <smcv@debian.org>, 574924@bugs.debian.org
Subject: Re: Bug#574924: RFP: oftpd -- A lightweight anonymous ftpd server daemon
Date: Fri, 2 Apr 2010 19:30:24 +0200
Hello,

fredag den  2 april 2010 klockan 02:00 skrev Simon McVittie detta:
> Note that oftpd was removed from Debian nearly 5 years ago (Bug #332186), a
> year and a half after the last release mentioned on
> <http://www.time-travellers.org/oftpd/>. It doesn't seem to have changed
> since. Please don't upload this to Debian unless you're willing to take over
> upstream development and security support.
> 
I am most grateful for this information. It will most
probably be the cause to interrupt my efforts, but I
will dig into matter of the above bug first.

Thank you very much.

> 
> Regards,
>     Simon


Regards

Mats Erik Andersson




Information forwarded to debian-bugs-dist@lists.debian.org, wnpp@debian.org:
Bug#574924; Package wnpp. (Sat, 10 Apr 2010 17:48:03 GMT) Full text and rfc822 format available.

Acknowledgement sent to Mats Erik Andersson <mats.andersson@gisladisker.se>:
Extra info received and forwarded to list. Copy sent to wnpp@debian.org. (Sat, 10 Apr 2010 17:48:03 GMT) Full text and rfc822 format available.

Message #24 received at 574924@bugs.debian.org (full text, mbox):

From: Mats Erik Andersson <mats.andersson@gisladisker.se>
To: 574924@bugs.debian.org
Subject: oftpd would need much scrutiny to pass the needles eye
Date: Sat, 10 Apr 2010 19:51:11 +0200
package wnpp
retitle 574924 RFP: oftpd -- a lightweight anonymous ftpd server daemon
owner 574924 markhobley@yahoo.co.uk
thanks


After pondering on the matter, I have decided to
waive the efforts needed to revive this software.

A renewed commitment to overcome old DoS flaws, and
possibly more, is not to be taken lightly. Personally,
I recommend a suitably arranged Proftpd service to
address the kind of service the RFP proposer probably
had in mind.


M E Andersson




Changed Bug title to 'RFP: oftpd -- a lightweight anonymous ftpd server daemon' from 'ITP: oftpd -- lightweight anonymous FTP server' Request was from Mats Erik Andersson <mats.andersson@gisladisker.se> to control@bugs.debian.org. (Sat, 10 Apr 2010 17:48:04 GMT) Full text and rfc822 format available.

Owner changed from Mats Erik Andersson <mats.andersson@gisladisker.se> to markhobley@yahoo.co.uk. Request was from Mats Erik Andersson <mats.andersson@gisladisker.se> to control@bugs.debian.org. (Sat, 10 Apr 2010 17:48:05 GMT) Full text and rfc822 format available.

Removed annotation that Bug was owned by markhobley@yahoo.co.uk. Request was from Bart Martens <bartm@debian.org> to control@bugs.debian.org. (Wed, 06 Jun 2012 00:39:17 GMT) Full text and rfc822 format available.

Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Apr 23 18:39:56 2014; Machine Name: beach.debian.org

Debian Bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.