Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 19 Jan 2002 14:48:07 -0500
From:      "Joe & Fhe Barbish" <barbish@a1poweruser.com>
To:        "Alfatrion" <alfatrion@cybertron.tmfweb.nl>
Cc:        "FBSD Questions" <questions@FreeBSD.ORG>
Subject:   RE: telnet/ftp security
Message-ID:  <LPBBIGIAAKKEOEJOLEGOGEBJCNAA.barbish@a1poweruser.com>
In-Reply-To: <14920284908.20020119173205@cybertron.tmfweb.nl>

next in thread | previous in thread | raw e-mail | index | archive | help
I only access the FBSD/gateway/ipfw box from ms/windows 
machines. You implied the SSH(v2) and sftp are the 
equivalent encrypted versions of telnet & ftp. 
Are these windows clients, and if so where do I get 
them from?

I read the man skey and it's assocated other commands 
man pages. As usual these man pages lacks any how to 
setup and use info. 
Is there any how-to-use infor you can point me to?

Thanks 
Joe  

-----Original Message-----
From: Alfatrion [mailto:alfatrion@cybertron.tmfweb.nl]
Sent: Saturday, January 19, 2002 11:32 AM
To: Joe & Fhe Barbish
Cc: FBSD Questions
Subject: Re: telnet/ftp security

Hello Joe,

Saturday, January 19, 2002, 5:08:57 PM, you wrote:

JFB> I have telnet & FTP ID/PW access to my FBSD gateway/ipfw
JFB> box from the internet. Are there any security holes in
JFB> these two applications that would allow breaking into my system?

The biggest security holes in those application is the lack of
security. Both application send the usernames, passwords and the data
unencrypted. All one has to do is sniff the username and passwords to
gain access to the system. SSH(v2) and sftp are the equivalent
encrypted versions. (a lot of other procolls are unsave to, like pop3,
smtp, ect.)

I have my machine set up so that it can not be reached from the
internet with telnet, but did leave other procols untouched. To
compromis for this i installed the use of one-time-use password, for
certain users. You can check 'man skey' for this.

--
Best regards,
 Alfatrion                            mailto:alfatrion@cybertron.tmfweb.nl


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?LPBBIGIAAKKEOEJOLEGOGEBJCNAA.barbish>