Home | Contact Us | FAQ | Search & Site Map | Link to Us
Sign In | Join | Other 45 Sites in Network
Home
Discussion GroupsWindows Server 2003Windows 2000Windows NTSmall Business ServerVirtual ServerExchange ServerIISHost Integration ServerISA ServerSMSWSUSMOMWindows Media ServerSecurityCertification
Related Topics
SQL ServerMS WindowsMS OfficePC HardwareMore Topics ...

Windows Server Forum / IIS / IIS Security / August 2006

Tip: Looking for answers? Try searching our database.

remove users from ftp site

Thread view: 
Enable EMail Alerts  Start New Thread
Thread rating: 
cmyar - 28 Aug 2006 13:34 GMT
just amde a ftp server.  iis 6.0  box sits on the ISP outside the firewall.  
going over the windows firewall log i notice that even though I renamed the
administrator account when using it as a username ftp accepts it.  I have
also disallowed anonymous connections and when using anonymous as a user ftp
still says it accepts the username.  is this normal behavior or did I miss
something in the security setup?
Funkadyleik Spynwhanker - 28 Aug 2006 15:12 GMT
Are you actually logging in with the Administrator account?

The FTP service seems to accept connections and not reject for a username,
instead coming up with the default "authentication denied" thing.

I assume that is to prevent the brute force guessing of usernames and is
expected behavior.  Likewise for the IP address restriction, it doesn't
disallow for making a connection, but rules out logging in at all.

> just amde a ftp server.  iis 6.0  box sits on the ISP outside the
> firewall.
[quoted text clipped - 5 lines]
> still says it accepts the username.  is this normal behavior or did I miss
> something in the security setup?
cmyar - 28 Aug 2006 15:24 GMT
no i can't log in with the administrator account.  it still concerns me that
the administrator account and the anonymous user are accepted users

> Are you actually logging in with the Administrator account?
>
[quoted text clipped - 14 lines]
> > still says it accepts the username.  is this normal behavior or did I miss
> > something in the security setup?
Bernard Cheah [MVP] - 29 Aug 2006 04:54 GMT
Well, it just like unknown users to the FTP server.
Of coz it will still accept it, but it will not authenticate it
successfully.

You can't prevent someone to knock on your door, right?

Signature

Regards,
Bernard Cheah
http://www.iis.net/
http://www.iis-resources.com/
http://msmvps.com/blogs/bernard/

> no i can't log in with the administrator account.  it still concerns me
> that
[quoted text clipped - 22 lines]
>> > miss
>> > something in the security setup?
Funkadyleik Spynwhanker - 29 Aug 2006 17:08 GMT
> no i can't log in with the administrator account.  it still concerns me
> that
> the administrator account and the anonymous user are accepted users

Ok, well you are misunderstanding the issue then.

Rejecting Users = bleeding data to an attacker.  Telling them "Yes exists,
or No does not exist".  If you get any kind of auditing, you will get dinged
for that as it opens you up to all sorts of social engineering attacks as
well as a focused brute force attack on the existing accounts.  A single
variable isolated (the username) makes the problem to a "couple of months"
problem from a "longer than the universe has existed" problem.

Not rejecting users = giving them _nothing_ to start getting a foothold on.

You are thinking the first one is safer than the second one, which is
incorrect.  The server should simply fail to login in _exactly_the_same_way_
no matter what it is that is wrong.  Anything else, and you are giving away
information you don't want out there.  You deleted the administration
account, now why do you want to ADVERTISE that fact?
 
Sign In
Join
My Latest Posts
My Monitored Threads
My Blog
My Photo Gallery
My Profile
My Homepage

Start New Thread
Enable EMail Alerts
Rate this Thread



©2010 Advenet LLC   Privacy Policy - Terms of Use
This website includes both content owned or controlled by Advenet as well as content owned or controlled by third parties.