RE: Accessing the File server

From: Dave Killion (Dkillion_at_netscreen.com)
Date: 08/29/03

  • Next message: Gabriel Orozco: "Re: Accessing the File server"
    To: "'Kanwar Sidhu'" <Kanwar.Sidhu@anu.edu.au>, security-basics@securityfocus.com
    Date: Fri, 29 Aug 2003 08:54:23 -0700
    
    
    

    Kanwar,

    There'll always be a 'hitch' with security - even the most commonly-used
    'secure' protocols (SSL, SSH, etc) occasionally will have security
    problems. The best you can do is pick something appropriately secure, and
    then keep tabs on it - make sure it's up to date, and monitor it for
    suspicious activity.

    I'd recommend SSH as a secure way of sending files. This service may
    already be installed on your server by default - it's a common service to
    have running. There are a variety of programs that support this protocol
    in file-transfer mode - Putty (Free-as-in-Beer) has a pscp command-line
    program to transfer files, while SSH Corporation's client (Not Free) has a
    slick drag-and-drop very similar to Explorer. If you have other POSIX
    OS's in your environment (Linux, *BSD, Solaris, etc) then the OpenSSH
    client is for them, and also comes generally pre-installed.

    Check out OpenSSH at www.openssh.org.

    Good luck!

    I hope this information is helpful,

    Dave Killion
    Senior Security Engineer
    NetScreen Security Group, NetScreen Technologies, Inc.

    -----Original Message-----
    From: Kanwar Sidhu [mailto:Kanwar.Sidhu@anu.edu.au]
    Sent: Thursday, August 28, 2003 10:56 PM
    To: security-basics@securityfocus.com
    Subject: Accessing the File server

    Hi There,
    I got file server Red Hat Linux that is accessible only inside from my
    organization. I am just wondering is there any kind of secure method so
    that people can access files from the outside world without any hitch
    with security. I was thinking is there any kind of web interface method
    so that people just enter there user names & get access to files. But
    this I think will involve running web server which I don't want to do.
    Is there any other solution out there ???

    Thanks,

    Kanwar Sidhu

    ---
    Outgoing mail is certified Virus Free.
    Checked by AVG anti-virus system (http://www.grisoft.com).
    Version: 6.0.512 / Virus Database: 309 - Release Date: 8/19/2003
    --------------------------------------------------------------------------
    -
    Attend Black Hat Briefings & Training Federal, September 29-30 (Training),
    October 1-2 (Briefings) in Tysons Corner, VA; the world's premier
    technical IT security event.  Modeled after the famous Black Hat event in
    Las Vegas! 6 tracks, 12 training sessions, top speakers and sponsors.
    Symantec is the Diamond sponsor.  Early-bird registration ends September
    6.Visit us: www.blackhat.com
    --------------------------------------------------------------------------
    --
    
    



  • Next message: Gabriel Orozco: "Re: Accessing the File server"

    Relevant Pages

    • Re: [Full-disclosure] Why Vulnerability Databases cant do everything
      ... best to relegate programming to a ... is a big difference between these two views of information security. ... but not nearly as important as designing secure systems. ... My favorite example to illustrate this point - ssh. ...
      (Bugtraq)
    • Questions on secure remote access to Fedora Core 2
      ... I am somewhat new to Internet security solutions in general and Linux ... I am setting up a server with Fedora Core 2 (there are specific reasons ... What is the most secure method I can use to give these individuals access ... under ssh. ...
      (comp.os.linux.security)
    • Re: Masking/Hiding a password in Perl Source
      ... While this is not a "secure" solution, obscuring the password or reading ... Using a protocol like SSH is ... This really is a false sense of security. ...
      (comp.lang.perl.misc)
    • Re: X Windows security
      ... I know that a machine is much less secure when X ... >How secure are vncserver sessions and X over ssh? ... Security Admin's Guide/Linux Security HOW-TO this evening. ... The How-To recommends using XDM. ...
      (Debian-User)
    • Re: X Windows security
      ... I know that a machine is much less secure when X ... >How secure are vncserver sessions and X over ssh? ... Security Admin's Guide/Linux Security HOW-TO this evening. ... The How-To recommends using XDM. ...
      (Debian-User)