Interview Questions

FTP server security

Computing Security,Information Security, NT security, Web Security and Network Security Questions and Answers


(Continued from previous question...)

FTP server security

There is known problems with the FTP server that ships with Windows NT. There is another FTP server that comes with the Internet Information Server, IIS, that is supposedly more secure.

As stated elsewhere in this document, logging is not turned on by default. To turn on logging of the FTP server, there are a number of registry key parameters that can be changed. They are located under the following key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\FtpSvc\Parameters

Some of the parameters are LogAnonymous, LogFileAccess, LogNonAnonymous.

See Microsoft's articles on how to turn on * Better logging in the FTP server. * Accessing the root directory. * Access Rights for Anonymous Users of FTP Server * LogAnonymous Does Not Always Make an Entry in System Log

(Continued on next question...)

Other Interview Questions