all groups > iis ftp > june 2006 >
You're in the

iis ftp

group:

How secure is ftp user isolation on XP SP2


How secure is ftp user isolation on XP SP2 Thomas Jespersen
6/27/2006 12:00:00 AM
iis ftp: Hi



I have a XP with SP2 running FTP.



By accident I discovered that if I create a user and a folder in the root of
the FTP site, with the exact same name, that folder becomes the root of the
user.



After a bit or Googling, I found that this is called "FTP User Isolation".
But I can't find any documentation on this working for XP SP2. but it seams
to work!



I would like to be confirmed that this feature ensures that 2 users under no
circumstances are able to access each others files (as long as the folder
for the user exists). Is that correct?



Thomas


Re: How secure is ftp user isolation on XP SP2 jeff.nospam NO[at]SPAM zina.com
6/27/2006 8:29:50 PM
On Tue, 27 Jun 2006 10:56:42 +0200, "Thomas Jespersen"
[quoted text, click to view]

It's not user isolation, it's a simple mapping of the home directory.
And it has nothing to do with security in any manner. That's what
NTFS permissions are for.

Re: How secure is ftp user isolation on XP SP2 Chris Crowe [MVP 1997 -> 2006]
6/28/2006 12:00:00 AM
I do not beleive that this is called FTP User isolation more User Home
Folders.

On Windows XP SP2 - your users will be able to cd \ and go back to the root
of the FTP Site and then change into other folders by default.

On Windows 2003 Server you can isolate users to their own FTP folders as
dicsussed in the June 2006 IIS Insider article I wrote.

http://www.microsoft.com/technet/community/columns/insider/default.mspx

--

Cheers

Chris Crowe [IIS MVP 1997 -> 2006]
http://blog.crowe.co.nz
------------------------------------------------


[quoted text, click to view]

Re: How secure is ftp user isolation on XP SP2 Thomas Jespersen
6/30/2006 1:07:17 AM
Hi Chris and Jeff

OK... thanks for the answers.

I won't use this as a security thing then.

Thomas

"Chris Crowe [MVP 1997 -> 2006]" <IISMVP2005@iisfaq.homeip.net> wrote in
message news:uKfsLYhmGHA.3880@TK2MSFTNGP02.phx.gbl...
[quoted text, click to view]

AddThis Social Bookmark Button