|
发表于 2002-9-30 14:25:16
|
显示全部楼层
llc , 有点可怕!
guest account = root
你的 guest 影射成 root ,有一点可怕,或者说有一点安全漏洞的。应该影射成 nobody 。
然后加上:
guest account = nobody
map to guest = Bad User
map to guest = Bad Password
我的 smb.conf 文件:
#======================= Global Settings =====================================
[global]
workgroup = linux
create mask = 0755
directory mask = 0755
# 由于 SAMBA 是一位欧洲人编写的,client code page 的缺省值是 850 (西欧)。
# 我们需要把它改成 936 (中文简体). {437 (USA)}
client code page = 936
map to guest = Bad User
map to guest = Bad Password
guest account = nobody
# ------- 同 windows 机器 的 winpopup 聊天 ---------
# 为了处理 WinPopup 信息, Samba 提供了 "message command"全局参数,它定义
# 了信息到来时 Samba 应采取的措施. 例如:
;
; message command = /bin/mail -s 'message from %f on %m' root <%s; rm %s &
message command = /usr/bin/linpopup "%f" "%m" %s; rm %s
#
# 寻找windows机器的先后循序:
name resolve order = host bcast wins lmhosts
local master = yes
# ------------------ 作域登录服务 ------------------
domain master = yes
preferred master = yes
domain logons = yes
# ------------------ 作域登录服务 ------------------
announce version = 5.0
announce as = Windows NT Enterprise Edition 5.0
log file = /var/log/samba/log.%m
max log size = 0
deadtime = 5
# 只要使用者有权限,即使目录不为空,也可以将它删除.
delete veto files = True
# 使得“Nimba Worm”类病毒写的文件对所有的客户机不可见(*.eml、*.nws、riched20.dll)。
veto files = /*.eml/*.nws/riched20.dll/*.bat/*.scr/*.pif/
# 同样使得“Klez Worm”类病毒写的文件对所有的客户机不可见(*.bat、*.scr、*.pif、*.rar等文件不是完全
是病毒写的)。
# 将目录“/proc”和“/dev”的内容显示为空。
dont descend = /proc, /dev
# 将时间解析设为2秒,是为了让 Visual C++ 更好地工作(作用于共享的 SMB 文件时)。
dos filetime resolution = True
# 当客户连接到一个服务时,指定运行的命令。
; preexec = csh -c echo \"Welcome to %S!\" | smbclient -M %m -I %I &
printcap name = /etc/printcap
load printers = yes
printing = lprng
max log size = 0
security = user
# ================ 要使 Samba 使用加密口令,必须加入以下参数: =================
encrypt passwords = yes
smb passwd file = /etc/samba/smbpasswd
# ====== 如果允许用户使用空口令,则应该使用如下参数:
; null passwords = yes
unix password sync = Yes
passwd program = /usr/bin/passwd %u
passwd chat = *New*password* %n\n *Retype*new*password* %n\n *passwd:*all*authentication*tokens*updated*successfully*
; obey pam restrictions = yes
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
wins support = yes
; wins proxy = yes
dns proxy = no
#============================ Share Definitions ==============================
[homes]
comment = Home Directories
browseable = no
writable = yes
valid users = %S
create mode = 0775
directory mode = 0775
# If you want users samba doesn't recognize to be mapped to a guest user
; map to guest = bad user
[公共文件]
comment = 公共文件夹
path = /var/ftp/pub
browseable = yes
writable = no
read only = yes
guest ok = yes
create mask = 0666
[RedHat]
comment = "RedHat 7.3 INSTALL
path = /mnt/gugong/RH_7.3/
guest ok = yes
[临时文件夹]
comment = 您可以复制您的文件到此目录
path = /var/ftp/in-coming/tmp
browseable = yes
writable = no
read only = yes
guest ok = yes
create mask = 0666 |
本帖子中包含更多资源
您需要 登录 才可以下载或查看,没有账号?注册
×
|