Re: Windows XP and FTP



Hi there Colin,

Thank you for your suggestion - I have tried this, and unfortunately opening ports 20 & 21 on the firewall as an exception does not seem to make a difference, even after a restart of both the connection and the client machine itself.



Kindest of regards,

Hamish Stanaway, CEO

Absolute Web Hosting / -= KoRe WoRkS =- Internet Security
Auckland, New Zealand

http://www.buywebhosting.net/
http://www.absolutewebhosting.biz/



From: Colin Bean <ccbean@xxxxxxxxx>
To: "koremeltdown@xxxxxxxxxxx" <koremeltdown@xxxxxxxxxxx>, security-basics@xxxxxxxxxxxxxxxxx
Subject: Re: Windows XP and FTP
Date: Wed, 11 Jan 2006 19:11:46 -0800
MIME-Version: 1.0
Received: from nproxy.gmail.com ([64.233.182.195]) by bay0-mc2-f6.bay0.hotmail.com with Microsoft SMTPSVC(6.0.3790.211); Wed, 11 Jan 2006 19:11:48 -0800
Received: by nproxy.gmail.com with SMTP id a27so183547nfc for <koremeltdown@xxxxxxxxxxx>; Wed, 11 Jan 2006 19:11:47 -0800 (PST)
Received: by 10.48.31.20 with SMTP id e20mr96465nfe; Wed, 11 Jan 2006 19:11:46 -0800 (PST)
Received: by 10.48.218.3 with HTTP; Wed, 11 Jan 2006 19:11:46 -0800 (PST)
X-Message-Info: JGTYoYF78jEfTrAn+9Ijq2hTHcETT88HnnUixBrQWgo=
DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:in-reply-to:mime-version:content-type:references; b=HGoky2KvTYEXzCxXE1m7v2VnIbA+R4/rHPgepnft+47bhLWIQ747eKYJ4pRjpQUFTRUhjuAUHlLwMYEyKk7nbtkTxN875+YrHPWx7L42CDi/y92RIJI7mWqCio4ZR59gnsV+3VkYyGagP8SI7gN1zvqN5rIKwXV+ZkUoLW+3Gvs=
References: <20060110011058.12554.qmail@xxxxxxxxxxxxxxxxx> <469858380601101448u68cb736ncfba7372cc02823e@xxxxxxxxxxxxxx>
Return-Path: ccbean@xxxxxxxxx
X-OriginalArrivalTime: 12 Jan 2006 03:11:48.0731 (UTC) FILETIME=[ED317CB0:01C61725]


Have you tried opening the FTP-related ports in the XP firewall (I beleive
that FTP needs port 21 and 20, one for control and one for data transfer)?
In the "add port" window, you can use "change scope" to limit connections to
your IP only, which should make the setup reasonably secure (besides the
fact that you're using FTP ;) ) Don't think this will help much with the
domain name issues, but it might help with the actual transfer.


hth,
-Colin

On 1/10/06, Mark Owen <mr.markowen@xxxxxxxxx> wrote:
>
> On 10 Jan 2006 01:10:58 -0000, koremeltdown@xxxxxxxxxxx
>
> **snip**
> > I could ask all of my XP using clients to just disable their XP Firewall
> when uploading their websites via FTP, but I don't think the more savvy
> customers would appreciate doing that (they are smart enough to realise what
> it means to disable a firewall on todays internet).
> > My question to the list is, does anyone know how to correctly configure
> XP Firewall to get around this issue, or is disabling the firewall the only
> way? I would like to include this in my FAQ, so the easier workthrough the
> better.
>
> Does not resolve? Well, I don't have a XP machine in front of me but
> you can goto the advanced section for the firewall settings and add
> your FTP client to an exception list. Or, in the same spot you can
> tell it to allow FTP to go through. I haven't had this kind of
> problem before but this may fix it.
>
> Generally, when one of our users have a FTP/Firewall issue, and they
> are using explorer as their FTP client, I have them enable Passive FTP
> by going to "Internet Options" - "Advanced" - and check "Use Passive
> FTP.." or likewise in what ever FTP client they may be using.
>
> --
> Mark Owen
>
>
> ---------------------------------------------------------------------------
> EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
> The Norwich University program offers unparalleled Infosec management
> education and the case study affords you unmatched consulting experience.
> Tailor your education to your own professional goals with degree
> customizations including Emergency Management, Business Continuity
> Planning,
> Computer Emergency Response Teams, and Digital Investigations.
>
> http://www.msia.norwich.edu/secfocus
>
> ----------------------------------------------------------------------------
>
>



---------------------------------------------------------------------------
EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE
The Norwich University program offers unparalleled Infosec management education and the case study affords you unmatched consulting experience. Tailor your education to your own professional goals with degree customizations including Emergency Management, Business Continuity Planning, Computer Emergency Response Teams, and Digital Investigations.


http://www.msia.norwich.edu/secfocus
----------------------------------------------------------------------------



Relevant Pages

  • Re: FTP server behind a PF firewall (including NAT)
    ... Philip> have exactly the same problem. ... Philip> huge range of high ports, and I can't find any information ... IPFW is a real pain compared to most modern firewall software. ... address-translate) the FTP data transfers. ...
    (comp.unix.bsd.freebsd.misc)
  • Re: Newbie question about ports.
    ... Can you do a CVSup to update your ports via http? ... Cvsup does not support http, but neither does it use ftp (see man cvsup, ... openable through your firewall. ...
    (freebsd-questions)
  • Re: Passive Mode issue
    ... in the windows firewall and the network firewall with the same results. ... and the ftp site is bound to a specific public IP. ... The server will timeout from all users trying passive mode. ... passive port range for IIS and opened those ports in the firewall, ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Passive Mode issue
    ... Bernard Cheah ... windows firewall for ftp, so it does fail with the firewall enabled, this ... Normally the FTP site is bound to the public IP, ... firewall ports, but i think i have all those correct. ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Problem about Window Xp SP2 firewall and the buildin FTP command
    ... Problem about Window Xp SP2 firewall and the buildin FTP ... I find a problem that if running multiple FTP command at the same ... Windows XP SP2 to limit Max Connections/sec ...
    (microsoft.public.windowsxp.general)