Ftp server a bit more secure ?

From: Frédéric Médery (fmedery@sympatico.ca)
Date: 10/05/01


From: Frédéric Médery <fmedery@sympatico.ca>
To: <focus-ms@securityfocus.com>
Subject: Ftp server a bit more secure ?
Date: Thu, 4 Oct 2001 19:25:39 -0400
Message-ID: <000001c14d2b$e1637a50$01df10ac@winxp>

Hello everybody,

I have to set a FTP server on a DC ! I know it's stupid but I'm not the
one who decided :-) And I have to disable anonymous access !

What I did :
Fully patched the Server
Installed IIS on a different partition.
Created a group called Web Designer
Created user who's not member of domain user group (just of web designer
group). To remove the domain user group, I set the Web designer group as
the primary group.
The IIS partition is only available for web designer and the iis admin
group.
Of course the users have log on locally.
I create one ftp root folder and some virtual directory that are not
childs of the ftp root. So users are unable to see other folder even if
they try to go to the root of the ftp site.

Can this be a more "secure" or less dangerous ftp server ? Is it good to
remove the ftp users from the domain user group ?
If you have some advice :-)

Thank you,
This ML is one of the best

Have a nice day

Fred



Relevant Pages

  • Re: Ftp server a bit more secure ?
    ... Ftp server a bit more secure? ... To remove the domain user group, I set the Web designer group as ...
    (Focus-Microsoft)
  • Re: Ftp server a bit more secure ?
    ... Ftp server a bit more secure? ... it sounds like you're not utilizing IIS in any manner that makes IIS ... To remove the domain user group, I set the Web designer group as ...
    (Focus-Microsoft)
  • SV: Ftp server a bit more secure ?
    ... Subject: SV: Ftp server a bit more secure? ... Why the reliance on MS IIS for FTP services? ... Created user who's not member of domain user group (just of web designer ...
    (Focus-Microsoft)
  • Re: Microsoft FTP Server problem on W2K?
    ... It is a UNISYS ClearPath mainframe system that is trying to FTP using ... passive mode to a MS FTP server. ... Currently the mainframe FTPs in ACTIVE mode. ... Since the mainframe pushes files to our customers over a WAN connection, ...
    (microsoft.public.inetserver.iis.security)
  • RE: FTP Upload
    ... FTP server to the following specified size. ... //set or get the remote path of the FTP server that you want to connect. ... //set the class MessageString. ...
    (microsoft.public.dotnet.framework.aspnet)