Re: FTP - Local or Redirect?

From: ME (trash.trash_at_comcastDOTnet)
Date: 07/23/03


Date: Wed, 23 Jul 2003 15:08:11 GMT

Folks, the problem & question is not "how to authenticate", rather it is how
to "CONNECT" to the server wether that be via a redirected port on the
firewall (redirected to an internal FTP server) or directly (the service
runs on the firewall. I have already decided to use simple FTP to
authenticate. As for smb the thought is samba would be involved in some
form to mount the network shares (think something along the lines of DFS) to
the FTP server.

thanks,

Matt

"Ida Young" <nospam@rogers.com> wrote in message
news:zpxTa.48450$zwL.40758@news04.bloor.is.net.cable.rogers.com...
> As Mike said, the main problem with FTP is sending user's credential in
> clear text over the network. You can set up ssh service in your FreeBSD,
and
> you and your frields can use sftp in UNIX and psftp from putty for Windows
> to download your files.
>
> Another way to solve the problem is to authenticate the users before your
> frields use ftp to download your files. I am not sure whether the firewall
> you are using supports User Authentication or not. ITShield firewall can
do
> it easily. You can set up a rule like: From Internet to
> your-ftp-server:21/TCP, using proxy_ftp, and Auth. Therefore, only users
> authenticated by the firewall can use ftp service.
>
> Ida Young
> http://www.itshield.com
>
>
> "Miha Pihler" <miha.pihler@Atlantis-N0Spam.si> wrote in message
> news:uqAHA5NUDHA.2200@TK2MSFTNGP11.phx.gbl...
> > The main problem with FTP is sending user's credential in clear text
over
> > the network. See if you can go around this with using SSL on your FTP
> Server
> > (your server has to support this options). By default this is not an
> options
> > with any of IIS versions (without using WebDAV).
> >
> > --
> > Mike
> > MCSA 2K, MCSE 2K, MCT, ...
> >
> > "ME" <trash.trash@comcastDOTnet> wrote in message
> > news:D%nTa.113046$sY2.49776@rwcrnsc51.ops.asp.att.net...
> > > I am would like to setup an FTP server for a select few of my family
and
> > > friends. My firewall is running FreeBSD 5.1 and natd. I have an
Win2k
> AD
> > > Domain Controller (yes for my own house, it makes things easier for
me.)
> > > behind the firewall. It seems I have two options for setting up the
FTP
> > > server:
> > >
> > > 1. I can run the FTP daemon on the firewall and mount the windows
> boxes
> > > to it using smbmount.
> > >
> > > 2. I can redirect (port redirection via NATD) the FTP traffic to the
> > Win2k
> > > box and mount the FreeBSD shares to it using Samba.
> > >
> > > The question is, which would be the best approach, both from a
security
> > > perspective as well as a performance perspective. I understand that
ftp
> > is
> > > not a secure protocol and I am willing to accept the risks involved
but
> I
> > > would like to limit them as much as possible.
> > >
> > > Thanks,
> > >
> > > Matt
> > >
> > >
> >
> >
>
>



Relevant Pages

  • Re: Being hacked...
    ... Are you offering a webserver and ftp server to users on the internet as per having ... FTP and HTTP open? ... For internet attacks what I would look for is patterns in the firewall ... I am not an expert on IIS by any means but I do know if you are using FTP and IIS you ...
    (microsoft.public.win2000.security)
  • Re: Bug with W2K3, SP1, Windows Firewall and FTP
    ... Port) in the Exceptions tab and uncheck the pre-defined FTP Server in the ... list and exception is allowed (of coz tight to the scope of your exception ... I decided to try adding a port 21 in the firewall exception list just to ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Bug with W2K3, SP1, Windows Firewall and FTP
    ... I only enabled the FTP Server service in advance settings. ... just the 'network connection setting' in the firewall advanced tab or you ... Windows Firewall behavior? ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Can Somone Tell Me If We Have a Hacker?
    ... your firewall to never see that stuff again. ... Those types of attacks DO work. ... beginners out there do that stuff thinking no one will find their FTP site. ... FTP server" which is probably not an option. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Terminal Server with 2 NICs
    ... What you should have done is purchase a Firewall Appliance that allows ... for it to be a PPTP/VPN server or to allow users to authenticate with it ... Calling an illegal alien an "undocumented worker" is like calling a ...
    (microsoft.public.windows.terminal_services)