FTP server security.

From: Michael Bellears (michael.bellears_at_staff.datafx.com.au)
Date: 11/11/03

  • Next message: Tom Burns: "Exchange SMTP Hole?"
    Date: Tue, 11 Nov 2003 12:04:32 +1000
    To: <focus-ms@securityfocus.com>
    
    

    We are running 2000 advanced server, hosting multiple virtual domains
    for clients, with FTP access via Virtual Directories.

    I have noticed that any user connecting via FTP, is dumped into
    "/username" - eg.

    # ftp xxx.xxx.xxx.xxx
    Connected to xxx.xxx.xxx.xxx.
    220 iis02 Microsoft FTP Service (Version 5.0).
    Name (xxx.xxx.xxx.xxx:mb): craig
    331 Password required for craig.
    Password:
    230 User craig logged in.
    Remote system type is Windows_NT.
    ftp> pwd
    257 "/craig" is current directory.

    If I perform a cd ../different_username, I am successfully dropped into
    that clients dir:

    ftp> cd ../1800contacts
    250 CWD command successful.
    ftp> pwd
    257 "/1800contacts" is current directory.

    Once in there, I am able to list, create, and delete - Obviously
    something I need to restrict!

    Is there anyway to 'jail' each user to there own directory tree? - i.e.
    once authenticated, they cannot perform a "cd ../whatever" - If not, is
    there a 'recommended' ownership/perms that will restrict access, but
    still allow browsing via the web?

    Regards,
    MB

    ---------------------------------------------------------------------------
    Network with over 10,000 of the brightest minds in information security
    at the largest, most highly-anticipated industry event of the year.
    Don't miss RSA Conference 2004! Choose from over 200 class sessions and
    see demos from more than 250 industry vendors. If your job touches
    security, you need to be here. Learn more or register at
    http://www.securityfocus.com/sponsor/RSA_focus-ms_031027
    and use priority code SF4.
    ---------------------------------------------------------------------------


  • Next message: Tom Burns: "Exchange SMTP Hole?"

    Relevant Pages

    • Re: FTP access via ISA(proxy)
      ... Packet Filters are only for what is run from the Proxy box itself and has ... nothing to do with Clients. ... It is the same with ISA. ... > The funny thing is I personally have Proxy 2.0 and can FTP via that.. ...
      (microsoft.public.isa)
    • Re: FTP access via ISA(proxy)
      ... Packet Filters are only for what is run from the Proxy box itself and has ... nothing to do with Clients. ... It is the same with ISA. ... > The funny thing is I personally have Proxy 2.0 and can FTP via that.. ...
      (microsoft.public.backoffice.smallbiz)
    • Re: IIS 6.0 FTP
      ... if your ftp is working first. ... So, go to the remote machine (which allow to connect to your iis server), go ... The ftp server connection msgs you posted, doesn't look like IIS FTP to me. ... clients are using an order entry program created in Microsoft access. ...
      (microsoft.public.inetserver.iis.ftp)
    • Re: IIS 6.0 FTP
      ... if your ftp is working first. ... So, go to the remote machine (which allow to connect to your iis server), go ... The ftp server connection msgs you posted, doesn't look like IIS FTP to me. ... clients are using an order entry program created in Microsoft access. ...
      (microsoft.public.inetserver.iis.ftp)
    • Re: SBS2000, ISA server, FTP does not work on clients
      ... I'm going to try disabling packet filtering on the ISA ... between the second NIC on the server and the broadband ... ftp of the clients working of course) as the 'firewall' ... >clients to use FTP services? ...
      (microsoft.public.backoffice.smallbiz2000)

  • Quantcast