iNET Interactive - Online Advertising Agency
          
FreeWebHostingTalk Forums  
Quick Links
Find a Host » HOST QUOTE | ISPcheck.com
 
 
Go Back   FreeWebHostingTalk > Main Forums > Running A Free Web Hosting Company > Secure FTP

Reply
 
Thread Tools
Old 10-16-2006, 07:49 PM   #1
ZendURL
Community Liaison
 
Join Date: Dec 2005
Posts: 551

ZendURL is offline
Default Secure FTP
Is using standard FTP a security risk, and if so should I switch to Secure FTP? I've had a user bring this question to me (about switching) and I am unsure if it would make any difference.
__________________
L4RGE.com Free NO ADS Hosting With Fully Featured cPanel, PHP, MySQL, and More!
TomorrowHosting.com One cent hosting, with great affiliate program for free hosting users.
Reply With Quote
Old 10-18-2006, 12:59 AM   #2
jcink
Senior Member
 
Join Date: Sep 2005
Posts: 142

jcink is offline
Default
Hmm my box is CentOS... I don't know what you mean by standard FTP?

I use Pure-FTPd which is very secure. The one that came with the box though was VSFTPd which stands for "Very Secure FTPd" and that is secure too. I didn't use vsftpd because I couldn't find a place to set quotas.

Pro-FTPd is the one FTP server that has had serious problems.

It's been a while since then, though.

Proftpd exploits found: (6)
http://secunia.com/product/1250/?task=advisories

Pureftpd exploits found: (1)
http://secunia.com/product/3655/

vsftpd exploits found: (a whopping... 0 )
http://secunia.com/product/6396/

Or do you mean like... FTPS

http://en.wikipedia.org/wiki/FTPS
Reply With Quote
Old 10-18-2006, 05:21 PM   #3
ZendURL
Community Liaison
 
Join Date: Dec 2005
Posts: 551

ZendURL is offline
Default
I use Pure-FTPd as well, and it is very secure. However my user quoted this forum post:

Quote:
FTP is insecure. Passwords are sent in plaintext for anyone to snoop.
SFTP is secure, but to use SFTP you generally have to give a user SSH access. Which is not always desirable.

So, to give a user SFTP access without SSH access, set their shell to /usr/libexec/openssh/sftp-server instead of /bin/sh or /bin/bash.

If your sftp-server is not there, use locate sftp-server to find it.
Basically through SSH. I personally do not want to install it since it gives a user SSH access. Really I was wondering if there were any REAL advantages to it (I understand the SSH disadvantage).
__________________
L4RGE.com Free NO ADS Hosting With Fully Featured cPanel, PHP, MySQL, and More!
TomorrowHosting.com One cent hosting, with great affiliate program for free hosting users.
Reply With Quote
Old 10-18-2006, 05:52 PM   #4
xeepo
Junior Member
 
Join Date: Jul 2006
Posts: 20

xeepo is offline
Default
Your user is totally correct, standard FTP send passwords in plain text so they could be 'sniffed' out.

I use SFTP for my personal sites but you definitely have to allow SSH access for the user. This is very unlikely with free hosting.
Reply With Quote
Old 10-18-2006, 08:32 PM   #5
jcink
Senior Member
 
Join Date: Sep 2005
Posts: 142

jcink is offline
Default
he is right...

but, I honestly don't think it's that big of a deal.
Reply With Quote
Old 10-18-2006, 08:58 PM   #6
ZendURL
Community Liaison
 
Join Date: Dec 2005
Posts: 551

ZendURL is offline
Default
Okay, that was mainly my question: Is it worth looking into? And it seems the answer is no.
Thanks
__________________
L4RGE.com Free NO ADS Hosting With Fully Featured cPanel, PHP, MySQL, and More!
TomorrowHosting.com One cent hosting, with great affiliate program for free hosting users.
Reply With Quote
Old 10-19-2006, 01:54 AM   #7
jcink
Senior Member
 
Join Date: Sep 2005
Posts: 142

jcink is offline
Default
threads like this make me really curious about this stuff, so this is what i've done.

i went and downloaded a packet sniffer, WinDump. I played around with it and I see how this thing works. I THINK this is the MAX that it can do (if not someone please correct me):

You can basically use it to monitor peoples stuff if you're on their same network. I did,

windump -a -w file.txt -i 2 -nN -xX -s 1500 host 192.168.1.(my number) and not port 5631

And it started monitoring my computer. I tried signing into FTP and viewing webpages and stuff, and checked file.txt and well... all that stuff was logged.... I could see my passes, etc. I did the same thing to my brother whos on my local network and got the same results.

I tried doing it to a friends IP address and they went to pages, but I couldn't see anything. Appears that this thing is a local network thing only.

So I can see this being a prob:

-If people DON'T take care of their wireless (cuz I could hookup to my neighbors thing right now which I know is insecure and probably steal info :S)
-If you have bad people on your local network (<_<)
-If someone installs a packet sniffer on your computer without you knowing it and has the info sent to them.
Reply With Quote
Old 10-19-2006, 06:19 PM   #8
ZendURL
Community Liaison
 
Join Date: Dec 2005
Posts: 551

ZendURL is offline
Default
Thanks for all of this info. I think I now understand it fully with what you just posted. Thanks
__________________
L4RGE.com Free NO ADS Hosting With Fully Featured cPanel, PHP, MySQL, and More!
TomorrowHosting.com One cent hosting, with great affiliate program for free hosting users.
Reply With Quote
Old 12-11-2006, 03:52 AM   #9
Utrust-Hosting
Junior Member
 
Join Date: Dec 2006
Posts: 13

Utrust-Hosting is offline
Default
For ssl secure ftp you would need a dedicated ip address and ssl installed on your site there priced at about $49 per year and you cant get them free
__________________
Utrust-Hosting.com - Free and great paid services
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is Off
HTML code is Off
Forum Jump

Advertisement:
 
     
 
 
 

Copyright © 2005-2007, FreeWHT.Com. All Rights Reserved.   Advertise on FreeWHT

Related iNET Interactive Sites:
Web Hosting Talk | Hosting Catalog | Hosting Tech | Hot Scripts

Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.