Two Plus Two Newer Archives  

Go Back   Two Plus Two Newer Archives > Other Topics > Computer Technical Help
FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Display Modes
  #1  
Old 08-29-2007, 11:20 PM
Cubswin Cubswin is offline
Senior Member
 
Join Date: May 2003
Posts: 4,979
Default Unsecured FTPs

Quick questions. Does an unsecured FTP pose any sort of security risk besides the content of the file that's being FTPed?

Thanks in advance!
Reply With Quote
  #2  
Old 08-29-2007, 11:26 PM
kerowo kerowo is offline
Senior Member
 
Join Date: Nov 2005
Posts: 6,880
Default Re: Unsecured FTPs

Probably depends on the security of the FTP server software you are using. It's a way into your system so it isn't going to be as secure as not having that port open on your machine. You are probably better off finding a file serving place on the web and letting them host it.
Reply With Quote
  #3  
Old 08-29-2007, 11:29 PM
nuclear500 nuclear500 is offline
Senior Member
 
Join Date: Aug 2004
Location: Madison, WI
Posts: 1,065
Default Re: Unsecured FTPs

By unsecured I assume you mean plain FTP and not FTP secured behind SSH?

All traffic, including login information (passwords etc) travel across the wire in plain text....
Reply With Quote
  #4  
Old 08-29-2007, 11:35 PM
Cubswin Cubswin is offline
Senior Member
 
Join Date: May 2003
Posts: 4,979
Default Re: Unsecured FTPs

Thanks for the response.

Let me clarify the situation a little more. I am pulling a file down from one vendor's FTP server and putting it on another vendors FTP server. The computer I am operating is on network that should be very secure as I work for a large association with tons of IT people. The content of the document I am moving does not contain any personal information and is unusable to anyone other than me and the receiving vendor. Basically, someone I work with is being a nit about the unsecured FTP (he is a not about many things) and saying this file should be sent FTPS. Assuming our IT department does their due diligence to secure our network, does this unsecured FTP pose any risk?
Reply With Quote
  #5  
Old 08-29-2007, 11:38 PM
Cubswin Cubswin is offline
Senior Member
 
Join Date: May 2003
Posts: 4,979
Default Re: Unsecured FTPs

I am pulling the file down FTP with SSH and uploading it with FTP.
Reply With Quote
  #6  
Old 08-29-2007, 11:48 PM
nuclear500 nuclear500 is offline
Senior Member
 
Join Date: Aug 2004
Location: Madison, WI
Posts: 1,065
Default Re: Unsecured FTPs

Technically yes. Realistically? Not so much.

If you aren't under the requirements of HIPPA or SOX then you wouldn't need to worry about it. They are more worried that the FTP transaction is plain text, so it can be captured on the wire at any point between vendor A and vendor B.
Reply With Quote
  #7  
Old 08-29-2007, 11:55 PM
Cubswin Cubswin is offline
Senior Member
 
Join Date: May 2003
Posts: 4,979
Default Re: Unsecured FTPs

So in layman's terms, the only compromise is to the content of the data and not to the network? Sorry if this seems very basic... this is all new to me. Thanks again for the help!
Reply With Quote
  #8  
Old 08-30-2007, 12:03 AM
nuclear500 nuclear500 is offline
Senior Member
 
Join Date: Aug 2004
Location: Madison, WI
Posts: 1,065
Default Re: Unsecured FTPs

Correct, the network is not in any kind of 'danger' You are opening an outgoing socket, not opening an incoming socket to the Internet.

It would take some really crazy [censored] to reverse an outgoing socket into accepting incoming.
Reply With Quote
  #9  
Old 08-30-2007, 08:00 AM
kerowo kerowo is offline
Senior Member
 
Join Date: Nov 2005
Posts: 6,880
Default Re: Unsecured FTPs

Tell the nit to write a business justification for requiring your customer to do a project to upgrade their FTP servers. Then ask him to document any known cases where the client of an FTP server was hacked into while uploading to the server. Then tell him his kung fu is weak sauce and steal his red stapler.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -4. The time now is 06:35 AM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, vBulletin Solutions Inc.