best way to secure an FTP server in IIS 5 and IIS in general ???

From: _Matt_ (matt.fahnestock@brconstserv.com)
Date: 02/12/03


From: "_Matt_" <matt.fahnestock@brconstserv.com>
Date: Wed, 12 Feb 2003 09:20:59 -0500


What is the best way to secure an FTP server in IIS 5 and IIS in general ???

 Right, now have it set up with 2 accounts... an ftp incoming account and an
ftp outgoing account with correct virtual directories and associated NTFS
permissions. Now, is there a way to deny the creation of directories (i.e.
stop hackers from creating the COM and LPT special directories) ???? Is
there a way to stop reading files and just view the directory contents... in
NTFS, just using list folder contents, returns a read error... Also, is
there a way to have the server place the files in a secure temporary
location (for the incoming folder) until the posts can by checked
automatically or manually by virus/trojan scanners and not immediately
post/run in the folder ???

These questions are in response to having the FTP server hacked and had to
reset up the entire server due to a trojan... So what is the best way to
secure IIS ??? Or should everyone just uninstall it and buy software that
supports SSL on the FTP server ????



Relevant Pages

  • Re: best way to secure an FTP server in IIS 5 and IIS in general ???
    ... How to secure any Windows computer, including IIS: ... > NTFS, just using list folder contents, returns a read error... ... > These questions are in response to having the FTP server hacked and had to ...
    (microsoft.public.inetserver.iis.security)
  • Re: Locked out users still can ftp
    ... > the account is locked out. ... If I restart the IIS services then the ... think you would need to use a third party FTP server to try to do otherwise. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Wndows authorisation for an FTP server
    ... I have XP Pro but I don't understand 'IIS'. ... does 'anonymous account ' mean that anyone can log in to the computer ... I'd like the FTP server to recognize me and then ... > The account used to login will be displayed on the Security Accounts tab ...
    (microsoft.public.windowsxp.general)
  • Re: Locked out users still can ftp
    ... IIS caches user tokesn after login. ... >> the account is locked out. ... The problem is I can still>> login via ftp. ... > Also, even if you switch from IIS to another FTP server, most of the servers> out there have the same security problems, e.g. you need to install the> latest patches and you need to be careful to remove anonymous user access> from being able to both read and write to any folder. ...
    (microsoft.public.inetserver.iis.security)
  • FTP Server
    ... I have setup an FTP server with IIS on a Windows 2000 Server. ... how I can set it up so that the account I have created that has access to the ...
    (microsoft.public.inetserver.iis.security)