Re: Limiting FTP User Access

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Jeff Cochran (jeff.nospam_at_zina.com)
Date: 03/18/05

  • Next message: Gary: "FTP transfer issues"
    Date: Fri, 18 Mar 2005 14:46:34 GMT
    
    

    On Fri, 18 Mar 2005 05:39:13 -0800, "Chris Rose"
    <ChrisRose@discussions.microsoft.com> wrote:

    >Setting permissions keeps the limited user from logging in because the FTP
    >root shares the entire c:\ drive. I set up a virtual directory for the use
    >that I want to have limited access and set a path to be a subdirectory on the
    >c: drive such as c:\limited_user, but since NTFS permission prohibit the
    >limited user from access to c:\ then the user gets rejected when FTP'ing in
    >to the box.

    Not when used correctly. Limited user gets permissions on C:\ but
    nothing under the root except the folder they need access to. It's
    basic Windows permissions and security.

    Though why anyone would do this is beyond me. Set the user's home
    folder to the folder they need access to, or if this is on an XP box,
    see:

    How To Set Up an FTP Site So That Users Log Onto Their Folders:
    http://support.microsoft.com/default.aspx?scid=kb;EN-US;201771

    Also helpful:

    HOW TO: Set Up an FTP Server in Windows 2000
    http://support.microsoft.com/?id=300662

    HOW TO: Set Up an FTP Server in Windows Server 2003
    http://support.microsoft.com/default.aspx?scid=kb;en-us;323384

    HOW TO: Create a Secure FTP Directory that Uses Password
    Authentication:
    http://support.microsoft.com/?id=239120

    How To Limit Access to a FTP Site in Windows Server 2003:
    http://support.microsoft.com/default.aspx?scid=kb;en-us;816525

    INFO: FTP Site Administration Documentation in IIS 6.0:
    http://support.microsoft.com/default.aspx?scid=kb;en-us;814865

    Hosting Multiple FTP Sites with FTP User Isolation
    http://www.microsoft.com/resources/documentation/IIS/6/all/techref/en-us/iisRG_CFG_21.mspx

    Jeff

    >"Jeff Cochran" wrote:
    >
    >> On Thu, 17 Mar 2005 07:51:06 -0800, "Chris Rose"
    >> <ChrisRose@discussions.microsoft.com> wrote:
    >>
    >> >I come from the XP Embedded newsgroup, and it's been suggested to ask this
    >> >question here, since no on on the embedded newsgroup knows the answer.
    >> >
    >> >We have the IIS FTP server setup to allow us (the manufacturer) full access
    >> >to the C: drive using the Administrator account.
    >> >In addition to this we would like to setup FTP for the end-user to a specific
    >> >directory only. How do I do this with the IIS FTP server? Everything I've
    >> >tried ends up giving the user account full access to the C: drive.
    >>
    >> NTFS permissions.
    >>
    >> Jeff
    >>


  • Next message: Gary: "FTP transfer issues"

    Relevant Pages

    • Re: IIS 5, FTP, Different access permissions for different users
      ... with IP restricted 'intftp' login access, ... one thing i guess you don't need is the 'intftp' virtual directory. ... > My objective is to have internal users login> in as intFTP to write to outgoing folder and read ... > original default FTP site and created underthe new intFTP FTP site. ...
      (microsoft.public.inetserver.iis.security)
    • Re: FTP for roaming VPN client?
      ... > Assume that we have setup the VPN correctly so to make VPN user access ... > 1 - Setup FTP site on windows server. ... > 2 - Put the folder i want to share in the home directory. ...
      (microsoft.public.isaserver)
    • Re: FTP P
      ... I'm not really sure if I'm in user isolation mode, ... I run the IIS FTP Sites Wizzard to add a new FTP Site. ... that I defined previosly and have the full rights for this folder. ... If I delete the complete user, still delete for the other Virtual Directory. ...
      (microsoft.public.inetserver.iis.ftp)
    • Re: Digital transfers question. On topic. Geez. Whod have thunk it?
      ... I set up my own FTP site with a free download, ... computer and is immediately in a folder on his computer. ... I went over to the doctors office and interfered with that. ...
      (sci.med.transcription)
    • require password
      ... created virtual ftp site with its own folder directly below the 'inetpub' ... turned off anonymous access, created a user for the ftp site with ... same way with a different port than 21, ...
      (microsoft.public.inetserver.iis.ftp)