LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 06-05-2005, 09:59 AM   #1
Lin-For-All
LQ Newbie
 
Registered: Jun 2005
Posts: 12

Rep: Reputation: 0
VSFTP Secure?


Anythought on running VSFTP in a DMZ?
 
Old 06-05-2005, 02:21 PM   #2
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
In terms of vulnerabilities it is considered secure:
http://secunia.com/product/3268/

Just remember that unless you are using an ssl encrypted connection any passwords will be sent in plain text. As an anonymous ftp system it is perfect.
 
Old 06-05-2005, 05:51 PM   #3
Lin-For-All
LQ Newbie
 
Registered: Jun 2005
Posts: 12

Original Poster
Rep: Reputation: 0
Thanks for the info
 
Old 06-06-2005, 09:05 AM   #4
wdfears
LQ Newbie
 
Registered: Jan 2005
Posts: 12

Rep: Reputation: 0
would sftp be a good alternative to vsftp? as it would encrpt the data?
 
Old 06-06-2005, 09:22 AM   #5
Ephracis
Senior Member
 
Registered: Sep 2004
Location: Sweden
Distribution: Ubuntu, Debian
Posts: 1,109

Rep: Reputation: 50
Quote:
Originally posted by wdfears
would sftp be a good alternative to vsftp? as it would encrpt the data?
Use vsftp with ssl, that should work well for you.
 
Old 06-06-2005, 11:04 AM   #6
wdfears
LQ Newbie
 
Registered: Jan 2005
Posts: 12

Rep: Reputation: 0
is there any reason not to use sftp? is it not as secure? it is also just for personal use ie I do not have users accesses the server?
 
Old 06-06-2005, 12:30 PM   #7
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
sftp is more secure and I would recomend using it where possible. The only problem comes when people don't know about sftp or have sftp clients, if it is just for youself there should be no issue.
 
Old 06-06-2005, 01:12 PM   #8
sigsegv
Senior Member
 
Registered: Nov 2004
Location: Third rock from the Sun
Distribution: NetBSD-2, FreeBSD-5.4, OpenBSD-3.[67], RHEL[34], OSX 10.4.1
Posts: 1,197

Rep: Reputation: 47
Force the users to use sftp. WinSCP is so easy even a windows user can use it

You can also use something like scponly to put them in a chroot environment if that's needed.
 
Old 06-08-2005, 01:32 PM   #9
wdfears
LQ Newbie
 
Registered: Jan 2005
Posts: 12

Rep: Reputation: 0
Thought I would add this for any DreamweaverMX 2004 (v. 7.0.1) users out there. Dreamweaver has built-in SFTP client, select check the "Use secure FTP (SFTP)" option Not sure about earlier versions, but if I remember correctly I had to setup up putty and tunnel in somehow (a friend helped me set it up) in earlier version

Last edited by wdfears; 06-08-2005 at 01:34 PM.
 
Old 06-08-2005, 09:23 PM   #10
lowpro2k3
Member
 
Registered: Oct 2003
Location: Canada
Distribution: Slackware
Posts: 340

Rep: Reputation: 30
Thumbs up

Quote:
Originally posted by Ephracis
Use vsftp with ssl, that should work well for you.
I never thought of that either, thanks!
 
Old 06-08-2005, 09:28 PM   #11
lowpro2k3
Member
 
Registered: Oct 2003
Location: Canada
Distribution: Slackware
Posts: 340

Rep: Reputation: 30
Talking

Quote:
Originally posted by sigsegv
Force the users to use sftp. WinSCP is so easy even a windows user can use it

You can also use something like scponly to put them in a chroot environment if that's needed.
I wouldnt say that... I started an online intro OS class (-sigh- dont ask, lots of drama lol), and its basically learning UNIX from a Linux environment. It took quite a few people a little longer than I would have thought to learn WinSCP.

I'm willing to bet if we weren't in a class, and instead they were trying to download something off a website, they would have given up instead. We -need- putty/winscp to do our work in class, so they were forced

Instead of forcing your users to use program XYZ, they should force -YOU- to install server XYZ. In this case, VSFTPD over SSL, so you dont make users switch FTP clients that they've grown to love (especially web designers, do NOT make them switch their beloved FTP clients!! ) After all, we're the techies here right?
 
Old 06-08-2005, 10:14 PM   #12
sigsegv
Senior Member
 
Registered: Nov 2004
Location: Third rock from the Sun
Distribution: NetBSD-2, FreeBSD-5.4, OpenBSD-3.[67], RHEL[34], OSX 10.4.1
Posts: 1,197

Rep: Reputation: 47
No, not all of us. Techies answer the phone and say "Help desk, how can I assist you?"

Personally, I'm a systems engineer. My users don't dictate policy. I do.

 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
VSFTPD with secure & non-secure logins Ricci Graham Linux - Software 6 02-24-2020 11:49 PM
Secure email (SSL vs. secure authentication) jrdioko Linux - Newbie 2 11-28-2004 01:39 PM
little help with vsftp thanks a2carat Linux - Networking 2 01-30-2004 12:37 PM
vsftp, yes again cawpin Linux - Newbie 2 12-14-2003 01:37 PM
vsftpd very very secure, so secure i can't use it... baronsam Linux - Networking 4 10-06-2003 06:12 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:49 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration