Re: Mitigate FTP



Sorry Taufiq to pick on your post it was the one at the bottom.

Everyone is suggesting implementing an IPS/IDS. You should consider implementing an Network Intrusion Prevention System (NIPS) (http://en.wikipedia.org/wiki/Intrusion-prevention_system) dependent on your firewall technology and network topology this should not be to hard to implement. The NIPS system will detect the attack and either block the attack at the firewall or the router (dependent on router or firewall - i would consider firewall due to the router working pretty hard anyway).

As Taufiq has mentioned no matter what alternative service/protocol you may offer you will still get hammered.

As mentioned in a private email to you consider ACL's on the firewall to specific hosts if it is a B2B based service, also consider an ACL on the FTP to prevent access if the firewall is compromised or spoofed (it happens).

Stong password policies and non-default usernames (admin, veritas, backup, administrator, root, etc) are the way forward.

Sniffing will only be possible if the attacker is in the same network segment as your FTP service, on a vulnerable downstream or upstream router from yourselves or people who access the FTP.

Thanks

Matt.


Taufiq Ali wrote:
Hi Sarah,

I see no point having alternative to FTP just because some is trying to brute force it. Any alternative protocol like SFTP, SSH etc does not stop a person from doing a brute force. The ideal thing to mitigate this is to have a IPS/IDS or a Firewall that block the traffic coming from the pool of IP address used for attacks. Also harden the FTP box & enforce strong password policy. And bearing in mind the remote locations sniffing is not even worth considering.

Taufiq



-------- Original Message --------
Subject: Re: Mitigate FTP
From: David Glosser <david.glosser@xxxxxxxxx>
To: Sarah Wahl <scwahl@xxxxxxxxx>
CC: pen-test@xxxxxxxxxxxxxxxxx
Date: 10/15/2008 1:27 AM

how about using something like moveit (http://www.ipswitchft.com/)?

Clients still use ftp but then the file itself is transferred to your
actual ftp server?


On Mon, Oct 13, 2008 at 9:46 PM, Sarah Wahl <scwahl@xxxxxxxxx> wrote:
Hi All,
I am working with a company who is using FTP and cannot switch to a
better protocol. They have been seeing attacks which are most likely
coming from one person. The attacker is using four different IPs
(ARIN shows them to be coming from mexico, canada and the US) with the
same brute force attack. They are trying to guess user names using a
tool (don't know why they aren't just trying to sniff traffic). I have
suggested putting in a honey pot to try and catch the attacker and
they have locked down the service as best as possible given the fact
they are still having to use FTP. It is being run on IIS 6.0. The
attacker can't get through the firewall, so no damage so far. Do you
have any other suggestions for trying to catch the attacker and any
other mitigations? Any ideas would be greatly appreciated.

Thank you very much,
Sarah


------------------------------------------------------------------------
This list is sponsored by: Cenzic

Security Trends Report from Cenzic
Stay Ahead of the Hacker Curve!
Get the latest Q2 2008 Trends Report now

www.cenzic.com/landing/trends-report
------------------------------------------------------------------------



Relevant Pages

  • Re: Leopard Firewall Warning
    ... machines on a particular network can access a port. ... The new scheme is an XP-style application based firewall; ... This, as an example, allows an attacker, once ...
    (uk.comp.sys.mac)
  • Re: Cannot Access External http sites
    ... Pc can access network resources on the local lan and internet ... DNS queries work fine and so does FTP. ... This sounds very much like a firewall problem. ...
    (microsoft.public.windowsxp.network_web)
  • Re: 2nd try: Was Firewall problem: Only works on a restart.
    ... utilize the network, prior to bringing up the firewall what ... attacker some information about the sort of system you run. ... vulnerability emerges, the attacker has a list of potential targets. ... Now if you’re designing a firewall for someone like Apple or the ...
    (Fedora)
  • Re: 500 Access is Denied
    ... this is not ftp mode issue as you are getting 550 access denied. ... Is there a firewall or IP address restrictions on the server itself? ... internal network IP address bound to the network card on your SBS server ... From outside my firewall I can go to my external website via FTP client, ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Publisher 2003 FTP Proxy Settings
    ... I am doing this at home for my personal family website, so I am the network ... I'm not even sure if my PC is behind a firewall ?? ... >> that said that I cannot connect to the FTP server, my FTP Proxy settings ...
    (microsoft.public.publisher.webdesign)