Re: Windows Explorer may expose FTP passwords in plaintext



"Steve Riley [MSFT]" <steve.riley@xxxxxxxxxxxxx> wrote in message news:54DDFAE8-FFB4-4602-A4E1-ED414741F121@xxxxxxxxxxxxxxxx
I look at it this way... in the particular case of unencrypted FTP URLs, since the "userid:password" portion of the URL will be logged in cleartext in plenty of places besides the user's own profile, I don't see that there's much additional risk here.

I look at it this way... in the particular case of unencrypted FTP URLs, browsers - Internet Explorer included - have been woefully remiss in displaying and storing something that they know to be a password.

Perhaps it'd be a good idea to secure all of those places before implementing FTPS.

Alun.
~~~~
--
Texas Imperial Software | Web: http://www.wftpd.com/
23921 57th Ave SE | Blog: http://msmvps.com/alunj/
Woodinville WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers.
Fax/Voice +1(425)807-1787 | Try our NEW client software, WFTPD Explorer.


.



Relevant Pages

  • Re: Security Bug in IE
    ... >people print out the contents of FTP sites, ... [Please don't email posters, if a Usenet response is appropriate.] ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.security)
  • RE: ftp vs. webdav
    ... But saying that would require that you ignore the large number of FTP ... implementations that support the draft standard for FTP over SSL / TLS. ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.inetserver.iis.security)
  • Re: Windows Explorer may expose FTP passwords in plaintext
    ... Plenty of people use FTP securely - say, for instance, over an encrypted VPN, or over IPsec. ... Texas Imperial Software | Web: http://www.wftpd.com/ ... Woodinville WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.security)
  • Re: FTP, IIS 6, How to get the Logon Screen to prompt?
    ... >How to Enter FTP Site Password in Internet Explorer ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.inetserver.iis.security)
  • Re: SSL?
    ... FTP over SSL is most definitely possible. ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Washington WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.inetserver.iis.ftp)