Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | RE: securing an FTP service |
|---|---|
| Date: | Mon, 22 Nov 2004 19:25:03 -0500 |
Yes - VPNing to the location would over come the plain text password transferal along with encrypting all data coming off the FTP -----Original Message----- From: Davide [mailto:ak_71@libero.it] Sent: Monday, November 22, 2004 18:12 To: security-basics@securityfocus.com Subject: securing an FTP service Hi everybody. would you please give me some hints for the followin situation? In a win-based network, a folder contains some documents that have to be made available to company employees when they are not in the HQ but they are in a local branch office this is currently implemented by a FTP server (win 2kserver); the ftproot is the root dir of the documents. the server is connected to internet: (internet)---(router)---(firewall)---(LAN)---(server) employees access from a remote location office using their win logon credentials (no anonym access is provided). The local branch office acceses internet with a dinamic IP provided by ISP. What security concerns are rised in this setting? Should I use a DMZ, using the server to provide FTP services and moving the ftproot folder to another server INSIDE the DMZ (linked to a shared folder)? How can I overcome the problem that FTP passwords are transmitted not enchrypted? Should a VPN between HQ provide the panacea for these problems? thanks in advance davide --- Incoming mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.797 / Virus Database: 541 - Release Date: 11/15/2004 --- Outgoing mail is certified Virus Free. Checked by AVG anti-virus system (http://www.grisoft.com). Version: 6.0.797 / Virus Database: 541 - Release Date: 11/15/2004
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: studying guide/book for CISSP, Clement Dupuis |
|---|---|
| Next by Date: | RE: Spoofing an IP over the internet, David Gillett |
| Previous by Thread: | securing an FTP service, Davide |
| Next by Thread: | Re: securing an FTP service, Alessandro Bottonelli |
| Indexes: | [Date] [Thread] [Top] [All Lists] |