Practicing FTP Security



web hosting

One of the most highly sought after features on the web hosting market is FTP.   Short for File Transfer Protocol, FTP provides a means for transferring data from your computer to the web host’s server.  While the protocol is quite useful, FTP also presents many security risks and making yourself aware of them is crucial.

Beware of FTP Attacks

FTP is ideal for transferring files to a remote location.  However, you should know that in its purest form, this protocol is far from secure.  FTP transmits your data over a network in plain text.  If the transmission is intercepted, the contents of those files can be viewed by unauthorized parties.  Furthermore, a knowledgeable hacker can use the FTP server as an entrance into your website.  This is done by repeatedly trying to logon with an incorrect user password.  In most cases, the profile is disabled after reaching the maximum threshold of three sign in attempts, thus giving the hacker all the ammunition they need to launch the attack.

The most effective way to protect yourself from an FTP password attack is through the use of an FTP server logon exit program.  This mechanism can provide security in the following ways:

Rejecting logon requests by any user profiles that you have not granted FTP access to.  With the use of an FTP server logon exit program, the logon attempts from the profiles you decide to block are not counted towards the maximum sign in count.

Limiting the number of clients from which a user profile is able to access the FTP server.  For instance, if someone from accounting is granted access, you can make configurations where only users with an IP address from the accounting department have FTP access.

Recording the credentials and IP addresses of all FTP logon attempts.  This allows you to regularly view the activity of each FTP logon attempt.  If a profile is ever disabled for reaching the maximum count, you can use their IP address, identify the perpetrator and handle the matter accordingly.

FTP Security Recommendations

Because FTP is naturally insecure, you may want to strongly consider backing it up with a reliable security mechanism.  The most highly recommended is Secure Sockets Layer, or simply SSL.  SSL is an encryption protocol that enables secure communications between the FTP server and client.  It ensures that transmissions are encrypted, maintaining confidentiality and integrity for all data that passes through.  This includes files as well as usernames and passwords.  Most FTP severs support SSL through the use of a digital certificate which also provides additional security with client authentication.

Though some recommend the use of anonymous FTP for the sharing of non-confidential data, this can be an even greater security risk.  With anonymous FTP, anyone can upload to your server without a username or password.   They could be transferring pirated software or malicious files.  Before taking such a gamble, be sure to weigh all the risks and take the appropriate measures to ensure that your FTP communications are secure.

Tags: , , , , , ,

SSL For Your E-commerce Site

web hosting

With credit card fraud and identify theft on the rise, consumers are more cautious than ever about shopping online.  If you are running a store online, this means that potential customers are more reluctant to buy products and services from your site. ...

Mar 6th, 2009 Read more

Fighting Back Against Website Attacks

web hosting

Despite all the advancements that have been made in information security, hacking attacks continue to be a major problem, inflicting damage on some of the biggest companies.  Every year, it seems as if we hear a story where some major company has been...

Feb 19th, 2009 Read more

Why Hackers Hack Websites

web hosting

Security experts and various studies reveal that website hacking is definitely on the rise.  Today’s hackers are more advanced than ever before, often working together in close-knit communities trading tips and tools with one another.  These twisted...

Feb 5th, 2009 Read more

Benefitting From VPS Hosting

web hosting

Virtual Private Server or VPS, refers to a type of hosting where different customers host their sites a single physical server. They share the same internet connection and even the hardware itself. Sounds pretty much like shared hosting, right? Yes it...

Feb 3rd, 2009 Read more

How to Find Secure Shared Hosting

web hosting

If you are looking to save money on building and managing a website, shared hosting may be the way to go.  Shared hosting is incredibly affordable these days, so much that you can have a personal or business website for just a couple of dollars a month.  ...

Jan 13th, 2009 Read more

The Insecurity of the Open-source CMS

web hosting

Open-source content management systems are incredibly popular these days.  Unfortunately, one issue that has always plagued this type software is security.  On the surface, it would seem as if open-source software is more secure than commercial products...

Dec 19th, 2008 Read more

Do You Need Dedicated Hosting?

web hosting

Has your online business grown to the point where it exceeds the offerings of a shared hosting environment?  If so, it might to time to upgrade to dedicated hosting.  Often referred to as a dedicated server, dedicated hosting is a solution where you...

Dec 12th, 2008 Read more

Ensim and Norseman Team Up

web hosting

Ensim Corporation, collaborative infrastructure and web hosting application provider, recently formed a partnership with Norseman Defense Technologies, a prominent solutions integrator.  The new business relationship was established to offer Ensim’s...

Nov 24th, 2008 Read more

VeriSign Passes a Tremendous Milestone

web hosting

Security is one issue that is on the mind of millions of website owners throughout the world.  It’s good to know that more people are paying attention to the risks and have taken the steps needed to secure their sites.  Earlier this year, VeriSign...

Nov 21st, 2008 Read more

The Vulnerability of PHP

web hosting

The PHP programming language has become one of the most efficient web development tools available.  First introduced in 1994, this language has literally been used to create millions of websites throughout the world.  While PHP offers the ability to...

Nov 4th, 2008 Read more

Page 4 of 41234

Stay in Touch with the Geeks

Our Community

Facebook
2277 Fans
Twitter
1423 Followers
FeedBurner
59 Subscribers

Submit News

Do you have an exciting story and want the world to hear it?

Submit a Story

  • 15K monthly visitors
  • PageRank 6
  • Alexa 11,000