Internet, Networking, and Wireless Discussion of networking, internet, and wireless including Apple's Airport products.

FTP security questions


Post Reply New Thread Subscribe

 
Thread Tools
sentofuno

 
Member Since: Jun 23, 2006
Posts: 53
sentofuno is on a distinguished road

sentofuno is offline
not sure if this applies to just leopard server or if its a general FTP question, sorry if its in the wrong place.


i understand FTP sends usernames and passwords in plaintext. on my LAN no security is really required beyond having a password (seriously, only i use it and no one knows what it is) but over the net, i use SFTP for security.

i cannot see an option in mac os server to deny logins that use only FTP. do i need to deny non-SFTP logins, or is it more a case of i can choose from the client side how much security is needed, not so much the server side?


its really just to set my mind at rest, and to gain a little more understanding of FTP. thanks in advance.

mac mini core 2 duo - 10.5.1 server
macbook core duo - 10.5.1 client
QUOTE Thanks
rman
Inactive Staff
 
rman's Avatar
 
Member Since: Dec 24, 2002
Location: Los Angeles, California
Posts: 12,591
rman has much to be proud ofrman has much to be proud ofrman has much to be proud ofrman has much to be proud ofrman has much to be proud ofrman has much to be proud ofrman has much to be proud ofrman has much to be proud ofrman has much to be proud ofrman has much to be proud of
Mac Specs: 2 x 3.0GHz Quad-Core, 6GB OS X 10.6.8 | 15in MacBook Pro 2.2GHz OS X 10.6.8 | 64GB iPad 2 WiFi

rman is offline
What you have found is true with any favor of Unix. That is one of the reasons that sftp exists. The only was a person going to get our pass word from using ftp is if they are siffing network traffic. Then they would have to decode the packet information. If you are using sftp only then you should not be concerned.

Life isn't about waiting for the storm to pass, It's about learning to dance in the rain!
QUOTE Thanks
sentofuno

 
Member Since: Jun 23, 2006
Posts: 53
sentofuno is on a distinguished road

sentofuno is offline
thanks for the reply

it brings up another question tho..

if the choice of FTP or SFTP is on the client side, and i may in the future allow access to other user accounts than my own, and i need to secure my share but *cannot assume the 2nd user knows anything about network security, AT ALL*, ie cannot trust them to always use SFTP rather than FTP, is the only way to be secure to double triple check the permissions for the shares allowed to users?


say if someone gets a hold of the 2nd user's credentials, they can only access what 2nd user can access (which while limited is more than what i'm comfortable with), is there no other way of making it more secure in order to prevent this? no other way to ensure 2nd user uses security or they are denied?


sorry if i'm asking you to repeat yourself, but this is a security concern for me.


also come to think of it, nothing prevents the user *sending* credentials in plaintext, ie attempting to login, is there? i am not clear on this but if the 2nd user attempts login with FTP and someone was using a packet sniffer, thats the end of the story right? apologies again if you already answered my question!


thanks

mac mini core 2 duo - 10.5.1 server
macbook core duo - 10.5.1 client
QUOTE Thanks
PerryLynch

 
PerryLynch's Avatar
 
Member Since: Sep 24, 2007
Posts: 235
PerryLynch has a spectacular aura about
Mac Specs: 17" MacBook Pro 4GB

PerryLynch is offline
As I understand it, SFTP uses Secure Shell (SSH) as both the transit and encryption method. That being the case, you don't need to run an FTP server at all, just a properly-configured SSH service and the SFTP service. This way, all authentication and file transit traffic is encrypted. If you are running both FTP and SFTP now, try disabling FTP and connecting as you normally do with your SFTP client. If it works, your work is done ;-)

Perry

Perry M Lynch, CISSP CISA
Mac Newbie, Security not-so-newbie
QUOTE Thanks

Post Reply New Thread Subscribe


« Airport express wireless printing with Sky broadband | Powerbook G4 wireless printer help... »
Thread Tools

Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off
Forum Jump

Similar Threads
Thread
Thread Starter
Forum
Replies
Last Post
Tiger security settings questions ICFire OS X - Operating System 1 07-27-2007 09:21 AM
VPN Troubles shane440 OS X - Apps and Games 0 10-04-2005 11:08 AM
Security Questions Nathanb OS X - Operating System 2 06-11-2005 07:11 AM
OS X.26 - FTP allows login, but then closes after cwd to folder funky Web Design and Hosting 2 01-27-2005 11:43 PM
iBook Security, Cost & Efficiency Questions & Concerns Gideon Apple Notebooks 5 12-28-2003 02:33 PM

All times are GMT -4. The time now is 07:10 PM.

Powered by vBulletin
Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
X

Welcome to Mac-Forums.com

Create your username to jump into the discussion!

New members like you have made this community the ultimate source for your Mac since 2003!


(4 digit year)

Already a member?