securing IIS 5.0 FTp server

mobogasm

Golden Member
Oct 25, 1999
1,033
0
0
Can someone point me to some tips on securing IIS 5.0 for FTP server only use? I already have all service pack updates/hot fixes/security patches. Thanks.
 

wetcat007

Diamond Member
Nov 5, 2002
3,502
0
0
I myself would recomend you use BulletProof FTP 2.15 (for ftp serving), but I guess it's personal preference.
 

mobogasm

Golden Member
Oct 25, 1999
1,033
0
0
Thanks for the recommendation but I don't really have a choice in this situation.

How come when I disable anonymouse access for the FTP server it says that it will cause all passwords to be transmitted in clear text???? What am I doing wrong? I do not want anonymous access nor do I want passwords to be transmitted in clear text.
 

Poontos

Platinum Member
Mar 9, 2000
2,799
0
0
You cannot really secure IIS 5.0 FTP server.

For the most part, MS FTP is based on the standard FTP protocol, which, by itself does not encrypt authentication traffic, therefore, all FTP communication is transmitted in clear text. There is no way around this with MS FTP, and the majority of FTP server daemons unless of course, a third party encryption protocol like SFTP is utilized. However, this of course means that your clients need to utilize software that supports FTP encryption.

You can download Serv-U FTP server for personal use for free the last I checked. It's an extremely rock solid FTP server platform/solution.

If you have absoultely NO choice but to stick with IIS FTP (difficult for me to understand ), try here.
 

jleon

Senior member
Feb 1, 2001
215
1
81
The files transfer protocol (ftp) is inherently insecure, just like telnet. It uses cleartext password and there is no way to change that. There are work-arounds that people have used such as ftp over an established vpn tunnel, etc.

Best bet is what Poontos mentioned. Research into setting up a ssh server/service and use sftp (secure ftp). There are windows versions of it as well.

g'luck!
 

Fallen Kell

Diamond Member
Oct 9, 1999
6,097
461
126
ROFLMAO.... Security on IIS? Those two things are mutually exclusive (i.e. you can't have them both at the same time).
 

Poontos

Platinum Member
Mar 9, 2000
2,799
0
0
Originally posted by: Fallen Kell
ROFLMAO.... Security on IIS? Those two things are mutually exclusive (i.e. you can't have them both at the same time).
Funny. Point me to a properly setup Windows 2000 Server with IIS locked down, that is hacked.
 

wetcat007

Diamond Member
Nov 5, 2002
3,502
0
0
Originally posted by: Poontos
Originally posted by: Fallen Kell
ROFLMAO.... Security on IIS? Those two things are mutually exclusive (i.e. you can't have them both at the same time).
Funny. Point me to a properly setup Windows 2000 Server with IIS locked down, that is hacked.

microsoft.com had their dns servers attacked sucessfully about 6 months ago, lol just showing u something, nothing is 100% secure linux, apache and so on hjave all had their share of security breaches.
 

mobogasm

Golden Member
Oct 25, 1999
1,033
0
0
ok back to my original question, lets stop the flame wars microsoft vs linux etc. I just want to lock this thing down as much as possible regardless of how well it is locked down as compared to another ftp server.
 

Poontos

Platinum Member
Mar 9, 2000
2,799
0
0
Originally posted by: mobogasm
ok back to my original question, lets stop the flame wars microsoft vs linux etc. I just want to lock this thing down as much as possible regardless of how well it is locked down as compared to another ftp server.
Click on the "here" link in my original post.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |