Securing an FTP Server

File Transfer Protocol or FTP is one of the original core protocols of the Internet and was first documented in 1971. It was designed to provide the functionality to exchanges files over the Internet and is specified in RFC 959. 1 It is still currently used for a number of purposes, including running user and anonymously authenticated FTP servers for the provision of files and applications for download. For example, it is utilized by software vendors to provide updates or patches to clients. It is also used to transfer of files between disparate systems, for example many non-Unix systems also support the. | This chapter is provided on an as is basis as part of the Apress Beta Book Program. Please note that content is liable to change before publication of the final book and that neither the author s nor Apress will accept liability for any loss or damage caused by information contained. Copyright 2004. For further information email support@ All rights reserved. No part of this work may be reproduced in any form or by any means electronic or mechanical including photocopying recording or by any information storage or retrieval system without the prior written permission of the copyright owner and the publisher. Chapter 10 Securing an FTP Server File Transfer Protocol or FTP is one of the original core protocols of the Internet and was first documented in 1971. It was designed to provide the functionality to exchanges files over the Internet and is specified in RFC It is still currently used for a number of purposes including running user and anonymously authenticated FTP servers for the provision of files and applications for download. For example it is utilized by software vendors to provide updates or patches to clients. It is also used to transfer of files between disparate systems for example many non-Unix systems also support the FTP protocol. One of the most common uses of FTP is by ISPs to provide customers with the ability to upload files to their web sites. At first look FTP would seem to fulfill a useful and practical function. Unfortunately FTP is also inherently insecure. The only security available to most FTP sessions is a username and password combination. By default FTP transactions are conducted unencrypted and all traffic is sent in clear-text across your network. This includes the transmission of user names and passwords. This exposes you to a considerable level of risk that is difficult to mitigate with available tools. Due to the inner workings of FTP it is not possible to use tools such as Stunnel to secure FTP traffic and we ll .

Không thể tạo bản xem trước, hãy bấm tải xuống
TỪ KHÓA LIÊN QUAN
TÀI LIỆU MỚI ĐĂNG
Đã phát hiện trình chặn quảng cáo AdBlock
Trang web này phụ thuộc vào doanh thu từ số lần hiển thị quảng cáo để tồn tại. Vui lòng tắt trình chặn quảng cáo của bạn hoặc tạm dừng tính năng chặn quảng cáo cho trang web này.