Level Extreme platform
Subscription
Corporate profile
Products & Services
Support
Legal
Français
FTP Site Security
Message
From
08/06/2001 11:29:02
George Simon
GS Data Technologies, LLC
Cincinnati, Ohio, United States
 
General information
Forum:
Microsoft IIS Server
Category:
Other
Miscellaneous
Thread ID:
00516286
Message ID:
00516946
Views:
10
>I would turn off Anonymous access if you need any security at all... then just create users with privelages to each site.

Thanks for the response, Wayne.

Here is something I read from an IIS4 Administration book regarding your suggestion...

"With FTP, the only alternative to anonymous access is for the user to access the site using a valid Windows NT user account. The problem is that with FTP authentication, the username and password are transmitted as clear text (i.e., unencrypted). Anyone running Network Monitor or some other protocal analyzer on your network would be able to trap user credentials and a security breach would result. For this reason, FTP sites should generally be set for anonymous access, and this should be the only authentication scheme allowed."

Administering IIS4 by Mitch Tulloch

So, unless I'm missing something here, IIS4 doesn't seem to have the FTP Security model that will accomplish my goals. Any thoughts?
George Simon, MCP
Previous
Next
Reply
Map
View

Click here to load this message in the networking platform