Firewall Wizards mailing list archives

Re: The yearly FTP rant (Was: Re: Passive FTP and NAT/PAT with PIX and Serv-U)


From: "Patrick M. Hausen" <hausen () punkt de>
Date: Thu, 4 Apr 2002 09:57:21 +0200 (CEST)

Hi all!

mjr wrote:

It would appear that it is again time for my FTP rant, so I'm
redirecting my response back to the list.

Actually, this is firewall-wizards' first FTP rant of the new millenium. :)
...and done with such style, too!!

It would be a fine sign of progress if vendors stopped shipping FTP
and replaced it with scp/ssh. Someone ought to write a version of scp
that has exactly the same interface as FTP (but none of the network
protocol) and then we could invisibly swap it out and have done with
this most horrible bodge of a protocol...

We tried that recently. Actually with current OpenSSH implementations
and the sftp subsystem, there is a way to replace FTP.
F-Secure sells a really fine Windows client for drag&drop file
transfer over sftp connections. It's part of the F-Secure SSH2
product.

The downside: at the moment I haven't found a way to use it as an
actual replacement for FTP on our webserver. Customers updating their
virtual servers' htdocs directory are chrooted inside their part
of the filessystem tree. I haven't found a way to achieve this
with sftp: simple chroot and _no_ shell access.

Regards,
Patrick M. Hausen
Technical Director
-- 
punkt.de GmbH         Internet - Dienstleistungen - Beratung
Scheffelstr. 17 a     Tel. 0721 9109 -0 Fax: -100
76135 Karlsruhe       http://punkt.de
_______________________________________________
firewall-wizards mailing list
firewall-wizards () nfr com
http://list.nfr.com/mailman/listinfo/firewall-wizards


Current thread: