Re: My FTP access is very unsecure - advice requested

From: BerkHolz, Steven (spamtrap_at_Astrumtech.com)
Date: 11/03/04


Date: Wed, 3 Nov 2004 14:13:40 -0500

Do you have security set at the folder level for each user's folder?
Windows 200 will put them into their folder, but not restrict cd .. .
If not, it is most likely a legitimate user purposely storing things in the
wrong folder.

Look at the owner of the file. Who is it?

-- 
Steven BerkHolz
Send to Domain TESCOGroup dot com, username SB
Note: you may also want to know that you should never send mail to:
blacklist-my-ip@admins.ws
info@dautrap.uceprotect.net
listme@sorbs.net
spamtrap@sandes.dk
spamtrap@stop.mail-abuse.org
spamtrap@frankenbiker.de
spamtrap@blars.org
"Fernando L. Arredondo" <FernandoLArredondo@Yahoo.com> wrote in message
news:0k9id.1284$nD6.760@fe2.texas.rr.com...
>
> Thank you for answering my questions, I was really going mad this morning.
>
> > There are tools available to the miscellaneous hackers out there that
will
> > search random IP addresses for FTP servers that are open to abuse.  They
> > tend to use the "anonymous" or "ftp" account.
>
> When I first leased my webserver, I learned almost immediately not to
allow
> anonymous write access to ftp (or http for that matter).
>
> > Have you checked the logs to ensure that these files are being created
in
> > the way you think?
>
> I've never examined the logs but I will enable them for future reading.
>
> > If the account whose password you changed is IUSR_<machine-name>, note
> > that changing the password has no effect on users' ability to log on,
> > because that account exists to allow anonymous logons to proceed.
>
> I never use accounts like that other than the default for http reading.
For
> ftp, I create a Windows user account and grant that account ftp read/write
> access.
>
> > There are secure FTP servers available for even less than that - I'm
sure
> > some of the others here can recommend their personal favourites, but it
> > would be inappropriate for me to do so.
>
> I was thinking about checking with the dedicated server company on
upgrading
> to a W2003 Server since it allows IP sharing for ftp (isolation mode).
Will
> W2003 allow, by default, for us to secure ftp accounts even if the IP is a
> shared IP used by other websites and ftp sessions or is other 3rd party
> software still necessary?
>
> Thanks again for your assistance.
>
>


Relevant Pages

  • RE: FTP Accounts
    ... Create the new account, give them NTFS access to the ftproot folder and any ... when they first logon to the FTP server. ... | Content-Class: urn:content-classes:message ...
    (microsoft.public.inetserver.iis.security)
  • Separate Anonymous Access User to prevent FTP browsing?
    ... I have several virtual webs running in the same FTP root folder. ... With this setup, a user can authenticate with their FTP account, browse from ... - Point the WWW virtual web at that same folder. ...
    (microsoft.public.inetserver.iis)
  • Re: Windows 2003 Error need help
    ... A 3rd party FTP may be more secure. ... First you would want to rename your AD administrator account to something else, then create an administrator account in the domain, but only leave it in the Guest group, then disable the account. ... Thn create a user account on ServU called "administrator" on ServU, leave the password blank, create ab empty folder, then configure the administrator user account you created to use this emtpy folder as its home folder, then configure permissions to only Read. ...
    (microsoft.public.windows.server.networking)
  • Re: Secure FTP site
    ... Users must then provide a valid local account with ... For remote users to connect to the FTP service, ... You need to grant this right to any other ... the Administrative Tools folder. ...
    (microsoft.public.inetserver.iis.security)
  • My FTP access is very unsecure - advice requested
    ... I have allowed typical ftp access to users for a couple of years. ... I changed the password on this particular account (having ... I've looked into encrypted ftp but I am unsure ... are ftp servers available for about $500 for a very limited number of users. ...
    (microsoft.public.inetserver.iis.ftp)

Loading