summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorlassulus <lassulus@lassul.us>2017-08-01 18:05:53 +0200
committerlassulus <lassulus@lassul.us>2017-08-01 18:05:53 +0200
commitc5b90e82c88d5a98386ed2f2a3eaf5297f643446 (patch)
treeae2a58c72756d539d25307eaac449d8e653561c2
parente740022bc524a57dd671a5c714ab117b6331cf27 (diff)
parentf9811b2ea134d2a5e2dfa0afe8b55a717e601679 (diff)
Merge remote-tracking branch 'gum/master'
-rw-r--r--makefu/2configs/share/anon-ftp.nix31
1 files changed, 31 insertions, 0 deletions
diff --git a/makefu/2configs/share/anon-ftp.nix b/makefu/2configs/share/anon-ftp.nix
new file mode 100644
index 000000000..471f22cba
--- /dev/null
+++ b/makefu/2configs/share/anon-ftp.nix
@@ -0,0 +1,31 @@
+{ config, lib, ... }:
+let
+ ftpdir = "/home/ftp";
+in {
+ networking.firewall = {
+ allowedTCPPorts = [ 20 21 ];
+ autoLoadConntrackHelpers = true;
+ connectionTrackingModules = [ "ftp" ];
+ extraCommands = ''
+ iptables -A PREROUTING -t raw -p tcp --dport 21 -j CT --helper ftp
+ '';
+ };
+ systemd.services.vsftpd.preStart = lib.mkForce ''
+ mkdir -p -m755 ${ftpdir}/incoming
+ chown root:root ${ftpdir}
+ chown ftp ${ftpdir}/incoming
+ '';
+ services.vsftpd = {
+ enable = true;
+ extraConfig = ''
+ ftpd_banner=Welcome to the krebs share, use the incoming dir for new and old leaks. Join freenode#krebs
+ '';
+ anonymousUser = true;
+ anonymousUserNoPassword = true;
+ anonymousUploadEnable = true;
+ anonymousMkdirEnable = true;
+ writeEnable = true;
+ chrootlocalUser = true;
+ anonymousUserHome = ftpdir;
+ };
+}