Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Microsoft virtualization tools reinforce user's data center plans
Air traffic network glitch cleared-up for now
Cisco buys into e-mail with $215 million PostPath acquisition
Locked iPhones can be unlocked without a password
Baseball's video and secure telephone links ready for instant replay
China aims for petaflop computer in 2010
Mozilla garners praise over Firefox security feature
Mt. Sinai Medical Center looks to open standards for patient smartcards
Immersion to pay Microsoft $20 million to settle patent suit
Expand Networks secures $8.5 million in venture capital
Alcatel-Lucent intros Gigabit Ethernet switches
Storage market thrives in down economy
Hosted RFID service targets mobile users
Best Western downplays data breach
Google drops Bluetooth, GTalkService APIs from Android 1.0
Security /

Securing FTP

Gearhead archive

We finished our discussion of FTP services last week by picking on everyone's favorite technology whipping boy, Microsoft. And this abuse was not gratuitous: The Microsoft FTP service in Internet Information Server (IIS) certainly isn't slick. It is also, as we discussed, not exactly security minded.

Where security is an issue, there are a few better systems to choose from. One interesting one is from Glub Tech.

The client side, which is free, is called Secure FTP. It supports secure connections to FTP servers that support Secure Sockets Layer (SSL). The company plans to add support for Kerberos and one-time passwords in future releases.

Advertisement:

The client, written in Java, requires Java 2 Runtime Environment Version 1.3+, and runs on Windows, Mac OS X and Unix. The client can run as an application or an applet (except with Mac OS X) when used in conjunction with Sun's Java Plug-In. This FTP client implementation only encrypts the command channel, so the data channel is not secured. If you want to be certain about the privacy of files, you'll have to encrypt them some other way. May we suggest Cryptext?

This freeware application integrates with the shell under Windows 95, 98, NT4, 2000 and Millennium Edition, so you can encrypt and decrypt files using the context menu (right mouse click). Cryptext uses a combination of SHA-1 and RC4 encryption algorithms with a 160-bit key.

How good is a 160-bit key? From the author's Web site: "We can make a small calculation on what is needed to break a 160-bit key. . . . With 160 bits in the key there are 2 to the power of 160 possible keys. It takes on the average, half that many attempts to find the correct key. [If] there are 1 billion computers in the world, [and] every computer is devoted full time to breaking your key, each computer can test 1 billion keys per second [and] . . . it will take about [100,000,000,000,000] years to find the key. "

Neat stuff. Anyway, back to FTP.

The FTP server has to understand SSL connection so Glub offers, for $30, its Secure FTP Wrapper, a Java front end for most FTP servers that intercepts requests on port 21. It unwraps SSL connections and passes on the commands to the FTP server and vice versa. The current version only supports Glub's Secure FTP client, but the company plans to support others.

A more developed SSL-enabled FTP server for Win 2000 and NT is WS_FTP from Ipswitch. It costs $400. WS_FTP Server has an extensive feature list, including many security attributes, and unlike the Microsoft IIS FTP service, the site command and stat command don't give anything away. One feature is the ability to have a program or batch file invoked whenever a specific event, such as a logon, occurs.

Ipswitch also has an FTP client called WS_FTP. The Pro version ($40) is SSL-enabled, has a slick user interface, scripting for automating routine tasks, sophisticated firewall support, multiple session support and browser integration.

Next week . . . well, we'll keep that secure.

Send your secrets to gearhead@ gibbs.com.

RELATED LINKS

Comments and suggestions to gh@gibbs.com.

Gibbs Forum
The place to discuss Gibbs's columns.

Check out this week's edition of

Backspin for more musings from Gibbs.

Part 1: Intro to FTP
Network World, 7/23/01.

Part 2: The connection to the server is made
Network World, 7/30/01.

Part 3: Connection modes
Network World, 8/6/01.

Part 4: Let the transfers begin
Network World, 8/13/01.

Part 5: FTP server security
Network World, 8/20/01.

Part 6: SITE and SYST
Network World, 8/27/01.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.