RE: FTP on IIS



Hi Lauren,

The very nature of FTP is insecure because the passwords used for
authentication are sent in the clear. Your best bet would be to use
some type of third-party FTP server/daemon that allows you to use FTP
over SSL. Currently IIS (v5.0 and 6.0) does not support this natively.
If you are stuck with IIS, then you could only allow FTP access via a
VPN. From there you can lock the site directories down using NTFS
permissions All in all there isn't a whole lot IIS can do natively to
"secure" an FTP site.

Just my $.02

Ryan
-----Original Message-----
From: listbounce@xxxxxxxxxxxxxxxxx [mailto:listbounce@xxxxxxxxxxxxxxxxx]
On Behalf Of lauren.malhoit@xxxxxxxxxxxxx
Sent: Friday, January 18, 2008 1:58 PM
To: focus-ms@xxxxxxxxxxxxxxxxx
Subject: FTP on IIS

I'm preparing to build a new FTP server using IIS (or an IIS server
using FTP??? I'm not sure). Anyway, I was wondering if anyone could
recommend some good sources on how to lock it down. I need to configure
it for an FTP site that anyone can get to and one that is password
protected. Thanks in advance!



Relevant Pages

  • Re: IIS 6.0 FTP
    ... The IIS is running, along with the FTP ... There is no other FTP service on this server. ... I understand your have the order entry program, ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: IIS 6.0 FTP
    ... Well IIS FTP does have such a feature, how to use it, I do not know. ... clients are using an order entry program created in Microsoft access. ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: IIS 6.0 FTP
    ... Internet Information Services (IIS) Manager ... The Security System detected an authentication error for the server ... I doubt IIS FTP has such feature. ... using the clients username and password, ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: IIS 6.0 FTP
    ... does not look like the behavior of an IIS FTP server. ... By default, IIS FTP ... using the clients username and password, ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: 100s of logon errors for MSFTPSVC, event id: 100
    ... Another good security measure if you need to host an FTP site ... You have FTP exposed to the outside world, hackers have seen it listening ... "somecompany.com" Of course if all of your users have strong passwords the ...
    (microsoft.public.windows.server.sbs)

Quantcast