Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 19 Jan 2002 14:04:10 -0600
From:      jacks@sage-american.com
To:        "Joe & Fhe Barbish" <barbish@a1poweruser.com>, "Alfatrion" <alfatrion@cybertron.tmfweb.nl>
Cc:        "FBSD Questions" <questions@FreeBSD.ORG>
Subject:   RE: telnet/ftp security
Message-ID:  <3.0.5.32.20020119140410.017908f8@mail.sage-american.com>
In-Reply-To: <LPBBIGIAAKKEOEJOLEGOGEBJCNAA.barbish@a1poweruser.com>
References:  <14920284908.20020119173205@cybertron.tmfweb.nl>

next in thread | previous in thread | raw e-mail | index | archive | help
Joe: SSH and sftp are FBSD. SSH should be already setup and running on your
FBSD machine and can be accessed from a Win client capable of ssh1/ssh2. It
accesses thru port 22.

You will need to install sftp on the FBSD server and setup the Win FTP
client to use ssh if you have one that can do so....

At 02:48 PM 1.19.2002 -0500, Joe & Fhe Barbish wrote:
>I only access the FBSD/gateway/ipfw box from ms/windows 
>machines. You implied the SSH(v2) and sftp are the 
>equivalent encrypted versions of telnet & ftp. 
>Are these windows clients, and if so where do I get 
>them from?
>
>I read the man skey and it's assocated other commands 
>man pages. As usual these man pages lacks any how to 
>setup and use info. 
>Is there any how-to-use infor you can point me to?
>
>Thanks 
>Joe  
>
>-----Original Message-----
>From: Alfatrion [mailto:alfatrion@cybertron.tmfweb.nl]
>Sent: Saturday, January 19, 2002 11:32 AM
>To: Joe & Fhe Barbish
>Cc: FBSD Questions
>Subject: Re: telnet/ftp security
>
>Hello Joe,
>
>Saturday, January 19, 2002, 5:08:57 PM, you wrote:
>
>JFB> I have telnet & FTP ID/PW access to my FBSD gateway/ipfw
>JFB> box from the internet. Are there any security holes in
>JFB> these two applications that would allow breaking into my system?
>
>The biggest security holes in those application is the lack of
>security. Both application send the usernames, passwords and the data
>unencrypted. All one has to do is sniff the username and passwords to
>gain access to the system. SSH(v2) and sftp are the equivalent
>encrypted versions. (a lot of other procolls are unsave to, like pop3,
>smtp, ect.)
>
>I have my machine set up so that it can not be reached from the
>internet with telnet, but did leave other procols untouched. To
>compromis for this i installed the use of one-time-use password, for
>certain users. You can check 'man skey' for this.
>
>--
>Best regards,
> Alfatrion                            mailto:alfatrion@cybertron.tmfweb.nl
>
>
>To Unsubscribe: send mail to majordomo@FreeBSD.org
>with "unsubscribe freebsd-questions" in the body of the message
>
>

Best regards,
Jack L. Stone,
Server Admin

===================================================
Sage-American 
http://www.sage-american.com
jacks@sage-american.com

"My center is giving way, my right is in retreat;
....situation excellent! ....I shall attack!"
===================================================

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3.0.5.32.20020119140410.017908f8>