nanog mailing list archives

Re: FTP with authentication to RADIUS


From: Andrew Brown <twofsonet () graffiti com>
Date: Fri, 5 Jan 2001 10:27:59 -0500


1) many versions of FTP make you system vulnerable to root cracks.

...which are problems that need to be fixed.  if you know of any...

2) There is NO way to run FTP in a SSH tunnel because it uses dynamic port
assignments.

well...that's not entirely true.  you can tunnel the command channel,
just not the data channel.

3) FTP logins are plain-text.

sure, which is why you tunnel them via ssh, or use ipsec.
actually...if you use ipsec, you can get the data protected as well.

For sharing files, with anonymous users, HTTP is much better (see:
http://files.dnso.net)

for sharing files with anonymous users, i'll always be using anonftp.

-- 
|-----< "CODE WARRIOR" >-----|
codewarrior () daemon org             * "ah!  i see you have the internet
twofsonet () graffiti com (Andrew Brown)                that goes *ping*!"
andrew () crossbar com       * "information is power -- share the wealth."


Current thread: