Re: securing an FTP service

From: Alessandro Bottonelli (a.bottonelli_at_axis-net.it)
Date: 11/23/04

  • Next message: Raphaël Rigo ML: "Re: securing an FTP service"
    To: security-basics@securityfocus.com
    Date: Tue, 23 Nov 2004 09:26:17 +0100
    
    

    On Tuesday 23 November 2004 00:11, Davide wrote:
    >
    > (internet)---(router)---(firewall)---(LAN)---(server)
    >
    the LAN is NATted? If so, you'll need to set Port Address
    Translation on the firewall/nat.

    > employees access from a remote location office using their win
    > logon credentials (no anonym access is provided). The local
    > branch office acceses internet with a dinamic IP provided by
    > ISP. What security concerns are rised in this setting?
    >
    First, you don't know your branch offices IP address in advance,
    so you cannot filter traffic based on source IP address.

    > Should
    > I use a DMZ, using the server to provide FTP services and
    > moving the ftproot folder to another server INSIDE the DMZ
    > (linked to a shared folder)?
    >
    I personally see this solution as being bad... You are moving
    company's data in the DMZ, not a good idea in principle...

    > How can I overcome the problem
    > that FTP passwords are transmitted not enchrypted? Should a
    > VPN between HQ provide the panacea for these problems?
    >
    VPN is a solution, maybe FTP over SSL is another (but I am not
    familiar with Microsoft to point you to a specific product, any
    takers?).

    Cheers

    -- 
    Alessandro Bottonelli, CISSP & BS7799 Lead Auditor
    AXIS-NET Privacy & InfoSec Consulting
    http://www.axis-net.it
    

  • Next message: Raphaël Rigo ML: "Re: securing an FTP service"

    Relevant Pages

    • Re: Binding FTP Server Service to Internal Network Card
      ... used to establish the VPN tunnel should be present in the AD. ... you can use some 3rd-party FTP applications such as WS_FTP. ... Microsoft CSS Online Newsgroup Support ... This newsgroup only focuses on SBS technical issues. ...
      (microsoft.public.windows.server.sbs)
    • RE: Prividing Intranet Website Access To External Users
      ... If you use VPN IPSec you get access to ALL lan, after you need start to close access, the one that remanis open is the problem, does you remember Murphy?. ... Can by installed in DMZ, double firewall, internaly and others. ... > The web server is IIS on windows2003. ... > intranets to the internet in a secure manner. ...
      (Security-Basics)
    • Re: OWA not seen from RWW Main Menu
      ... The RRAS wizard is indeed for VPN or modem dialup to your server. ... You don't check FTP, as you surely are not running FTP server on your box, ... But I will personally always use your shortcut to OWA. ...
      (microsoft.public.windows.server.sbs)
    • Re: VPN to ISA server, cant FTP through it
      ... FTP connection for that matter. ... Repeat the monitoring with the filter set to Client IP# as the FTP Server. ... through a VPN, will they not be encrypted anyway? ... then the Source Network would be the "created" Network that ws created when ...
      (microsoft.public.isa.vpn)
    • Re: Secure FTP
      ... > for VPN i was referring that client machine VPN to your ... > then secure all sort of communication, including FTP. ... >>Bernard Cheah ...
      (microsoft.public.inetserver.iis.ftp)