Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject:
PostPosted: Tue Sep 01, 2009 4:26 pm 
Offline
Senior Member
User avatar

Joined: Sun Feb 08, 2004 7:18 pm
Posts: 562
Location: Austin
Guspaz,

The suggestion wasn't to disable access to the "System" account (which should go without saying), but to have FTP logins that are completely separate from other logins in the system (like SSH).

Edit: bah! glg beat me to it. :-)


Top
   
 Post subject:
PostPosted: Tue Sep 01, 2009 5:06 pm 
Offline
Senior Member
User avatar

Joined: Tue May 26, 2009 3:29 pm
Posts: 1691
Location: Montreal, QC
True. That, of course, doesn't preclude the possibility of an FTP server exploit that might be made easier by the attacker having access to an FTP account. But does mitigate a lot of the risk.

I'd still urge that FTP is just a bad protocol to use in general, though; protocols that use cleartext authentication have no place on the net.


Top
   
 Post subject:
PostPosted: Tue Sep 01, 2009 5:09 pm 
Offline
Senior Member
User avatar

Joined: Sun Feb 08, 2004 7:18 pm
Posts: 562
Location: Austin
Agreed.


Top
   
 Post subject:
PostPosted: Tue Sep 01, 2009 9:35 pm 
Offline
Senior Member

Joined: Fri Jan 09, 2009 5:32 pm
Posts: 634
Guspaz wrote:
I'd still urge that FTP is just a bad protocol to use in general, though; protocols that use cleartext authentication have no place on the net.


no question. scp/sftp are just as easy to use


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 4 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group