all groups > iis ftp > september 2006 >
You're in the

iis ftp

group:

FTP log code 331


FTP log code 331 Mark Rae
9/27/2006 5:39:29 PM
iis ftp: Hi,

Can anyone please give me a definitive answer to the following:

Does the presence of an entry in the FTP log ending in 331 prove absolutely
and categorically that a successful connection was made to the FTP server,
or does it merely indicate that an *attempt* was made to connect using the
userid provided, and that a password was requested because anonymous access
was disabled.

I understand that a subsequent entry [with the same session number] ending
in 530 proves that the login attempt was unsuccessful due to an invalid
userid / password combination.

I also understand that a subsequent entry [with the same session number]
ending in 230 proves that the login attempt was successful, but this is not
logged by default.

I'd be particularly interested to know if there is any legal case history
where the above information was used.

Any assistance gratefully received.

Mark

Re: FTP log code 331 Bernard Cheah [MVP]
9/29/2006 12:00:00 AM
See if this helps.
http://msmvps.com/blogs/bernard/archive/2005/01/28/34050.aspx

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Re: FTP log code 331 Mark Rae
9/29/2006 12:00:00 AM
[quoted text, click to view]

Thanks very much.

Re: FTP log code 331 Mark Rae
9/30/2006 12:00:00 AM
[quoted text, click to view]

That was useful, thanks.

As you may have gathered from my original post, I'm investigating a
suspected case of hacking and/or FTP log tampering.

Regarding the FTP log on a Windows 2000 server, is the session identifier in
square brackets ALWAYS incremental? If it wasn't, i.e. there was an entry
missing, would that be symptomatic of the FTP log having been tampered with?

Any assistance gratefully received.

Mark

Re: FTP log code 331 Bernard Cheah [MVP]
10/1/2006 12:00:00 AM
Yes, it always be incremental. if FTP service got restarted, it will start
again.
And per your last question. errr. not so sure, but highly possible,
althought if ftp crashes in between or log didn't get flush to disk, you
will also have missing entry in between.

--
Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/


[quoted text, click to view]

Re: FTP log code 331 Mark Rae
10/1/2006 12:00:00 AM
[quoted text, click to view]

That's what I thought....

[quoted text, click to view]

That's very helpful - thanks.

[quoted text, click to view]

AddThis Social Bookmark Button