FTP Hacking

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Greetings all!

As a consultant I support 6 SBS 2003 machines. A few of these need to run an
FTP server which is fine except this is an attack target since there is no
time delay after unsuccessful login attempts.

I will find EventID 529 and 100 in the Event Viewer logs after these
attempts. My research has found that it is some scum sucking hacker using a
script that tries several userids and passwords umpteen times to hack into
your FTP server. Userid Administrator is the most frequently tried. More
details on these attempts are in C:\WINDOWS\system32\LogFiles\MSFTPSVC1. I
get hit with about 10 every second for several hours at a clip, which does
not do wonders for my internet bandwidth!

Here are a few things I have done to help me sleep better at night:
1. Renamed the server's administrator account.
2. Insured all users that have permission to FTP server have complex
passwords.
3. Went to http://blog.netnerds.net/index.php?s=banftpips.vbs and got
Chrissy LeMaire's script file - this collects and bans the IP addresses of
hacks trying to get in as administrator.
4. Disabled anonymous FTP access.

My big question: Is there any registry or policy setting or script I can use
to initiate a time delay after each unsuccessful FTP login attempt?

If anyone uses other methods to deal with this issue please reply!

Regards,
Bs.


.



Relevant Pages

  • Re: Phishing Attempt
    ... Confusion - above you say the script was in the home directory, ... was connecting to the ftp server on 58.105.225.59 using the same account ... remarks: This object can only be updated by APNIC hostmasters. ...
    (comp.os.linux.security)
  • Re: Script to automate FTP session, copy folders based on timestamp
    ... VBS script to login to a remote FTP server. ... timestamp. ... folders from the remote FTP to a local server. ...
    (microsoft.public.scripting.vbscript)
  • Re: fetch / wget problem
    ... > I'm trying to write a script which gets a file from remote FTP server. ... You may be able to do this with a .netrc in the user folder that's running ...
    (freebsd-questions)
  • Re: Red Hat FTP Commands - Unattended Script Help Needed
    ... I'm designing a script for my application to log into a ftp server, ... The client differs from OS X, ...
    (comp.os.linux.misc)
  • Re: Mappings disconnect on FTP server, cant run script when disconnec
    ... But -- we notice on the FTP server when we go to My Computer the mapping ... When this script tries to run the mapping is disconnected it can not drop ... can you tell me why mappings on my FTP server in a workgroup will disconnect ...
    (microsoft.public.windows.server.general)