MDDHosting Forums: 10/19/2009 - FTPES and FTPS functionality - MDDHosting Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

10/19/2009 - FTPES and FTPS functionality

#1 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 19 October 2009 - 06:27 PM

We've changed some FTP configurations and firewall settings to make sure that FTPES (http://en.wikipedia..../FTPES#Explicit) and FTPS (http://en.wikipedia....i/FTPS#Implicit) function perfectly on our servers and services.

This will allow you to upload/download your files over SSL.

Not many use this and as such this issue wasn't discovered until recently - we've updated all servers to allow this and all new servers provisioned will be configured as such.

If you have any questions, feel free to respond to this thread :)
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

#2 User is offline   skunkbad 

  • Newbie
  • Pip
  • Group: Members
  • Posts: 21
  • Joined: 15-October 09

Posted 19 October 2009 - 08:19 PM

View PostMikeDVB, on Oct 19 2009, 04:27 PM, said:

We've changed some FTP configurations and firewall settings to make sure that FTPES (http://en.wikipedia..../FTPES#Explicit) and FTPS (http://en.wikipedia....i/FTPS#Implicit) function perfectly on our servers and services.

This will allow you to upload/download your files over SSL.

Not many use this and as such this issue wasn't discovered until recently - we've updated all servers to allow this and all new servers provisioned will be configured as such.

If you have any questions, feel free to respond to this thread :)


Hey, thanks for making the change. I had a ticket in today regarding this issue.

I started using FTPES after having regular FTP passwords stolen by a virus on my network. We have taken the infected computer offline, but I learned a valuable lesson about using a secure FTP connection, and also that FTP passwords should never be stored in the FTP client.

There are a handful of viruses out there that sniff network traffic and steal FTP logins. The stolen FTP logins are sent to a bot network, and the computers on the network will log in and put in iframes and all kinds of malicious code. If the virus is on your own computer, it will steal the saved passwords you have in your FTP client.

My sites are not that large, but for somebody with a large site, the damage done can be devastating. Most people would probably think that it was a security vulnerability on the host machine, but this is not the case. In my case, it was my mom's computer downstairs.
0

#3 User is offline   MikeDVB 

  • Forum Administrator
  • PipPipPipPipPip
  • Group: Staff Administrator
  • Posts: 1,545
  • Joined: 27-September 08
  • Gender:Male
  • Location:Central Indiana, USA

Posted 20 October 2009 - 03:04 PM

View Postskunkbad, on Oct 19 2009, 09:19 PM, said:

Hey, thanks for making the change. I had a ticket in today regarding this issue.
No problem - it took us a few moments to discover and resolve for you but in the end I'm very happy with the outcome :)

View Postskunkbad, on Oct 19 2009, 09:19 PM, said:

I started using FTPES after having regular FTP passwords stolen by a virus on my network. We have taken the infected computer offline, but I learned a valuable lesson about using a secure FTP connection, and also that FTP passwords should never be stored in the FTP client.
Good advice indeed about not storing FTP passwords. Another thing you should do is rotating your password regularly - all of my passwords are rotated on a weekly basis.

View Postskunkbad, on Oct 19 2009, 09:19 PM, said:

My sites are not that large, but for somebody with a large site, the damage done can be devastating. Most people would probably think that it was a security vulnerability on the host machine, but this is not the case. In my case, it was my mom's computer downstairs.
Large or small, the damage can be devastating depending on what exactly the attackers do with your account. In the case of cPanel if they have your FTP information then they also have access to your cPanel unless you set up an alternate FTP account to use (which I personally suggest).
Michael Denney - MDDHosting, LLC - Professional Hosting Solutions
LiteSpeed Powered - Shared, Reseller, Semi-Dedicated, and VPS
Incremental R1Soft CDP Backups on all shared, semi-dedicated, and VPS services!
http://www.mddhosting.com/ - Follow us on Twitter!
0

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users