Groups | Blog | Home
all groups > iis security > february 2004 >

iis security : FTP Questions


Pat
2/5/2004 3:32:42 PM
I'm running one W2K box with IIS 5.0. I have 100 domains on it. I need
to have user have FTP access to their websites. I have a seperate
server I can setup as an FTP server , but I am looking at the best way
for security. these two server are in there own workgroups out on my
DMZ on my firewall. I was looking at a third party FTP product like
Serv-U. Would setting up the FTP server for none domain users and
having a mapped drive to my webserver for the domain user to be able
to FTP in and get to their domains work? If not, what solutions would
Pat
2/5/2004 4:46:42 PM
I setup the MS ftp, too time consuming and difficult to manage. Is
there an advantage to having Serv-U running on it;s own server just
for FTP , then mapping a drive to my web server for users to update
their websites. or is there a better way?

On Thu, 05 Feb 2004 20:58:28 GMT, jcochran.nospam@naplesgov.com (Jeff
[quoted text, click to view]
jcochran.nospam NO[at]SPAM naplesgov.com
2/5/2004 8:58:28 PM
[quoted text, click to view]

I prefer WSFTPD to ServU, but both will work fine. You can use the MS
FTP server, though features are lacking for your bneeds.

Leythos
2/5/2004 11:07:40 PM
In article <lp95201v5ied7f061rto4q9ikjq53nr779@4ax.com>,
htech@hotmail.com says...
[quoted text, click to view]

I'm running server zilla on several systems, while it does not work with
NTFS permissions, you can create groups of users, each user or group and
be directed to a folder, and there is also bandwidth throttling in it.

The FTP server in IIS, while it does work, if you create folders for
each user name they can still up one folder and see the others even if
they can't get into them.

For my solution I just setup a 500GB RAID 1, make partitions for each
web site and point the IIS Web site and the Serverzilla FTP for each
user at the partition - this way they can't go over their quota, and it
does not rely on the OS to make it happen.

Seems to work well.


--
--
spamfree999@rrohio.com
Pat
2/6/2004 6:19:12 AM
how many domains are you running? I can see it working with a dozen or
so, but not with 100. thanks

[quoted text, click to view]
Leythos
2/6/2004 12:15:39 PM
In article <80u6209ss6c6vc9gonrqhs9594l1iprmm1@4ax.com>,
htech@hotmail.com says...
[quoted text, click to view]

Assuming that you were going to bottom post, so that we could determine
who you were replying to, I'll assume that you asked me:

The number of domains doesn't matter - the software permits groups and
then users. You have to login as a user, but you don't have to belong to
a group - groups just make it easy to manage permissions.

The software for the FTP server does not use Windows Authentication, so
you don't have a limit to domains.

--
--
spamfree999@rrohio.com
Pat
2/6/2004 12:23:09 PM
[quoted text, click to view]
Pat
2/6/2004 2:18:58 PM
On Fri, 06 Feb 2004 19:18:59 GMT, jcochran.nospam@naplesgov.com (Jeff
[quoted text, click to view]

I have it on the web server now, but are there any security issues
running FTP on a webserver?
Pat
[quoted text, click to view]
jcochran.nospam NO[at]SPAM naplesgov.com
2/6/2004 7:18:59 PM
[quoted text, click to view]

Run it on the web server itself.

Jeff

[quoted text, click to view]
jcochran.nospam NO[at]SPAM naplesgov.com
2/6/2004 10:36:29 PM
[quoted text, click to view]

Of course there are. Just as there are security issues with running
FTP on a separate system that connects to the web server. Except that
running on the web server eliminates the second potentially insecure
box, the potentially insecure connection between boxes and so on.

You'll find that if you can't secure your FTP server on the same box
as the files available to it, you're certainly not going to secure it
any better with a second box involved.

Jeff

[quoted text, click to view]
Leythos
2/6/2004 10:58:18 PM
In article <7bj720d3fni0tmdarbic5vikcbu8uijgjk@4ax.com>,
htech@hotmail.com says...
[quoted text, click to view]

Yes, I setup a drive partition for each company that uses the space. If
they want to expand, I create a larger partition, copy the files,
repoint the session to it. This way I don't have to mess with NTFS or OS
accounts.

--
--
spamfree999@rrohio.com
alun NO[at]SPAM texis.invalid
3/11/2004 10:26:04 PM
In article <4025ae40.203150394@msnews.microsoft.com>,
[quoted text, click to view]

I'm hoping you mean WFTPD - I'd hate to lose a user.

Alun.
~~~~

[Please don't email posters, if a Usenet response is appropriate.]
--
Texas Imperial Software | Find us at http://www.wftpd.com or email
1602 Harvest Moon Place | alun@texis.com.
Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers.
AddThis Social Bookmark Button