LinuxQuestions.org
Review your favorite Linux distribution.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-29-2015, 08:18 AM   #1
ron7000
Member
 
Registered: Nov 2007
Location: CT
Posts: 248

Rep: Reputation: 26
FTP question - sftp vs ftps, SSH versus SSL and port numbers


so i asked yesterday in a different post about best ftp method, so far the one response was SFTP which is ftp over SSH, which i figured was the way to go.

But i need a sanity check on information i was given.
The sender sent me a document stating they have a new ftp server with better security and in order to connect I need a client capable of FTP over SSL and also can configure for Clear Command Channel.

I go through their connection instructions and they give the host ip along with port = 22, connection drop down box = SSH/SFTP. Then underneath that there's SSL options which is grayed out but the check boxes are enabled for SSL Listings, SSL Transfer, and CCC.

so now i am confused. Initially they state it's going to be an FTPS connection right? but then the settings they are using specifically port number is SFTP is it not? help me understand what's really happening here, and why this use of CCC ?
thanks.
 
Old 04-30-2015, 03:31 AM   #2
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,370

Rep: Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335Reputation: 2335
ftp is inherently insecure if people can access your ftp server. "Secure" ftp servers are a bitch to set up, in my experience.

stfp, ssh, and scp are all in the same family and much better security wise, but encrypt everything. If this is a home network, the encryption/decryption is a bit OTT security wise. If it's a public, attackable network, then sure use ssh/sftp.

SSL has been cracked as an encryption tool, and I have seen instructions telling people how to disable it. I don't know if it's that bad, but it's not perfect.
 
Old 04-30-2015, 12:30 PM   #3
howzer
LQ Newbie
 
Registered: Apr 2012
Posts: 4

Rep: Reputation: Disabled
Port 22 is the default SSH port, and specifically choosing the protocol in your client should mean the connection will definitely be using SSH/SFTP. A lot of people get confused about the difference between SFTP and FTPS and don't even know they're separate things. As far as the check boxes, my guess would be that they're always there and are just grayed out because they don't apply to your connection once you select SSH/SFTP.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Enabling SFTP & FTP over implicit/explicit TLS/SSL in Linux rajaniyer123 Linux - Server 5 11-08-2012 08:36 PM
[SOLVED] Firewall ports for FTPS (FTP over SSL) connection cccc Linux - Security 4 10-17-2012 02:41 AM
[SOLVED] SFTP versus FTP over SSH... what is what and how can I see the difference? fast-reflexes Linux - Server 7 07-14-2010 09:45 AM
ftp over ssl or ftps://.. dsids Linux - Security 4 07-20-2006 11:49 PM
sftp doesn't work in Konqueror after SSH/SSL upgrade Supernaut Slackware 4 10-28-2003 02:33 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:20 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration