Click here to get back home

Hacker

 HomeNewsGroups | Search | About
 microsoft.public.windows.server.security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content
Subject Author Date
Hacker John Parker 10-11-2007
|--> Re: Hacker Mathieu CHATEAU10-11-2007
|--> Re: Hacker jwgoerlich10-11-2007
  ---> Re: Hacker Bernard Cheah [...10-11-2007
  |   |--> Re: Hacker Mathieu CHATEAU10-12-2007
  |   `--> Re: Hacker Bernard Cheah [...10-12-2007
  | ---> Re: Hacker Bernard Cheah [...10-14-2007
  |   |--> Re: Hacker Mathieu CHATEAU10-14-2007
  `--> Re: Hacker Bernard Cheah [...10-16-2007
Get Chitika Premium
Posted by Leythos on October 11, 2007, 10:28 pm
Please log in for more thread options
qbernard@hotmail.com.discuss says...
> > Are you using MS FTP? If so, switch to FileZilla FTP server.
>
> I'm just curious about this... how would this helps? and MS FTP is
> vulnerable ?

MS FTP, if you're not using Anonymous access, and you should not be,
uses Windows accounts for authentication - bad move on a exposed server.

If you use FileZilla Server you don't have to create ANY windows
accounts for it and can create user/group accounts, IP limits, bandwidth
limits, read/write settings, etc....

I've used FileZilla Server on every exposed MS server that offers FTP
and found that we have no problems like we use to have with MS FTP.

Oh, and we don't do Front Page or Front Page Extensions.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)

Posted by Mathieu CHATEAU on October 12, 2007, 2:13 am
Please log in for more thread options
Hello,

you may add extra security to IIS FTP :
http://blog.netnerds.net/2006/07/ban-administrator-ftp-login-attemps/
http://www.codeproject.com/useritems/FTPSecurity.asp

This is addon VBS that monitor connections and blacklist bad IP

--
Cordialement,
Mathieu CHATEAU
English blog: http://lordoftheping.blogspot.com
French blog: http://www.lotp.fr


> qbernard@hotmail.com.discuss says...
>> > Are you using MS FTP? If so, switch to FileZilla FTP server.
>>
>> I'm just curious about this... how would this helps? and MS FTP is
>> vulnerable ?
>
> MS FTP, if you're not using Anonymous access, and you should not be,
> uses Windows accounts for authentication - bad move on a exposed server.
>
> If you use FileZilla Server you don't have to create ANY windows
> accounts for it and can create user/group accounts, IP limits, bandwidth
> limits, read/write settings, etc....
>
> I've used FileZilla Server on every exposed MS server that offers FTP
> and found that we have no problems like we use to have with MS FTP.
>
> Oh, and we don't do Front Page or Front Page Extensions.
>
> --
>
> Leythos
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> spam999free@rrohio.com (remove 999 for proper email address)


Posted by Bernard Cheah [MVP] on October 12, 2007, 2:41 am
Please log in for more thread options
Oh Well, that's the design which relies on windows accounts. I think the
concern should be more on how to 'secure' as well as renaming + NTFS
restriction etc when implementing IIS FTP. the new IIS 7 FTP component
supports none windows user and even able to hook up to asp.net membership
provider, etc.

bottom line is not the product, but rather how you deploy and configure it.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


> qbernard@hotmail.com.discuss says...
>> > Are you using MS FTP? If so, switch to FileZilla FTP server.
>>
>> I'm just curious about this... how would this helps? and MS FTP is
>> vulnerable ?
>
> MS FTP, if you're not using Anonymous access, and you should not be,
> uses Windows accounts for authentication - bad move on a exposed server.
>
> If you use FileZilla Server you don't have to create ANY windows
> accounts for it and can create user/group accounts, IP limits, bandwidth
> limits, read/write settings, etc....
>
> I've used FileZilla Server on every exposed MS server that offers FTP
> and found that we have no problems like we use to have with MS FTP.
>
> Oh, and we don't do Front Page or Front Page Extensions.
>
> --
>
> Leythos
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> spam999free@rrohio.com (remove 999 for proper email address)



Posted by Leythos on October 12, 2007, 9:36 pm
Please log in for more thread options
qbernard@hotmail.com.discuss says...
> bottom line is not the product, but rather how you deploy and configure it.

Actually, the problem is that after all of these years, that even
seasoned IT types misconfigure FTP as well as other services all the
time which leads to compromising the server. Few people misconfigure
FileZilla FTP and even fewer misconfigured FileZilla servers are used to
compromise the OS/Server.

I've seen hundreds of compromised Windows boxes because of Windows FTP,
not a single compromised FileZilla FTP server.

--

Leythos
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)

Posted by Bernard Cheah [MVP] on October 14, 2007, 12:18 am
Please log in for more thread options
yes - more IIS FTP are subjected for break in, but that's NOT because of the
product.
the issue is the element between the monitor and the chair.

anything product without proper configuration is subjected to attacks as
well.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://msmvps.com/blogs/bernard/


> qbernard@hotmail.com.discuss says...
>> bottom line is not the product, but rather how you deploy and configure
>> it.
>
> Actually, the problem is that after all of these years, that even
> seasoned IT types misconfigure FTP as well as other services all the
> time which leads to compromising the server. Few people misconfigure
> FileZilla FTP and even fewer misconfigured FileZilla servers are used to
> compromise the OS/Server.
>
> I've seen hundreds of compromised Windows boxes because of Windows FTP,
> not a single compromised FileZilla FTP server.
>
> --
>
> Leythos
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> spam999free@rrohio.com (remove 999 for proper email address)



Similar ThreadsPosted
hacker attempts? June 13, 2007, 10:10 am
Hacker locking my accounts March 16, 2008, 5:02 pm

Our other projects:

Art Dolls, Fairies and Mermaids - Sunnyfaces.net

Roy's Linux, Programming and Search Engines messages

1-Script XML SitemapXML Sitemap