<?xml version="1.0" encoding="UTF-8"?>

<rss version="2.0" xmlns:blogChannel="http://backend.userland.com/blogChannelModule">

<channel>
<title>security experts please explain in Security</title>
<link>http://www.dslreports.com/forum/r17324726</link>
<description></description>
<language>en</language>
<pubDate>Mon, 30 Nov 2009 13:28:43 EDT</pubDate>
<lastBuildDate>Mon, 30 Nov 2009 13:28:43 EDT</lastBuildDate>

<item>
<title>Re: security experts please explain</title>
<link>http://www.dslreports.com/forum/remark,17329486</link>
<description><![CDATA[<A HREF="/useremail/u/770196"><b>major marco</b></A> : <div class="bquote"><SMALL>said by  kracksmith <A HREF="/useremail/u/1041096"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>does somebody just run a certain sniffer monitoring program on a public IP ftp server, as easy as that? <br> </DIV>If s/he is that obstinate about it, then I say let your "customer" live and learn.  And what are you doing with clientele if you are not able to intelligently explain security issues.  I hope they aren't paying you for your dearth of expertise.   :uhh:<br><SMALL>--<br><B><A HREF="http://icasualties.org/oif/BY_DOD.aspx">The Toll</A></B><br><br></SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17329486</guid>
<pubDate>Thu, 23 Nov 2006 11:56:35 EDT</pubDate>
</item>

<item>
<title>Re: security experts please explain</title>
<link>http://www.dslreports.com/forum/remark,17329010</link>
<description><![CDATA[<A HREF="/useremail/u/1013038"><b>arleybls</b></A> : <div class="bquote"><SMALL>said by  kracksmith <A HREF="/useremail/u/1041096"><IMG SRC="http://i.dslr.net/bb/profile.gif" ALT="See Profile" BORDER=0 WIDTH=16 HEIGHT=11></A> :</SMALL><br><br>does somebody just run a certain sniffer monitoring program on a public IP ftp server, as easy as that? <br> </DIV>No it is not that easy...but it could be as simple as arp poisoning on the same server's subnet to more sophisticated attacks against one of the hops in which the traffic flows...or...maybe, wire tapping the media :-)<br><br>If your boss concern is performance, you could use IPsec to encrypt only, at least, the FTP's control/command channel (port 21), all data would still be sent in clear trough the data channel...]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17329010</guid>
<pubDate>Thu, 23 Nov 2006 10:28:13 EDT</pubDate>
</item>

<item>
<title>Re: security experts please explain</title>
<link>http://www.dslreports.com/forum/remark,17328905</link>
<description><![CDATA[<A HREF="/useremail/u/662411"><b>SoonerAl</b></A> : This thread may be of interest...<br><br>&raquo;<A HREF="/forum/remark,17185903">unsecure FTP</A><br><br>At a <B>bare minimum</B> you could use the built-in MS PPTP VPN server/client function with a strong password for the authorized users for simple but safe file access from a remote location.<br><SMALL>--<br>"When all else fails, read the instructions..."</SMALL>]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17328905</guid>
<pubDate>Thu, 23 Nov 2006 10:07:58 EDT</pubDate>
</item>

<item>
<title>Re: security experts please explain</title>
<link>http://www.dslreports.com/forum/remark,17328624</link>
<description><![CDATA[<A HREF="/useremail/u/327578"><b>hayc59</b></A> : Hello, and welcome<br>give it some time...these professionals<br>are preparing their turkeys!  ;)]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17328624</guid>
<pubDate>Thu, 23 Nov 2006 08:58:03 EDT</pubDate>
</item>

<item>
<title>Re: security experts please explain</title>
<link>http://www.dslreports.com/forum/remark,17328534</link>
<description><![CDATA[<A HREF="/useremail/u/1041096"><b>kracksmith</b></A> : anybody??]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17328534</guid>
<pubDate>Thu, 23 Nov 2006 08:23:57 EDT</pubDate>
</item>

<item>
<title>security experts please explain</title>
<link>http://www.dslreports.com/forum/remark,17324726</link>
<description><![CDATA[<A HREF="/useremail/u/1041096"><b>kracksmith</b></A> : Ok let's just saying one of my customer is running a IIS 6.0 FTP server (which he is by the way). <br>He doesn't want to be running any encryptions on the FTP server. I tell him this is dangerous and somebody can sniff out your clear text username and password. <br><br>he said he doesn't go into this FTP all the time but just seldomly plus he likes the IE FTP client, it's easy to use and it's available anywhere he goes. he doesn't want to rely on a encrypted ftp client which he needs to carry or download. <br><br>he also said if somebody where to sniff out his password that hacker has to know exactly when he's logging into the FTP server which he says is impossible. <br><br>i told him i read hacker can monitor his public and leave a sniffer there 24/7. he said how? i couldn't explain this since i'm not a hacker but from a security stand point i like to know how this is done? <br><br>does somebody just run a certain sniffer monitoring program on a public IP ftp server, as easy as that? ]]></description>
<guid isPermaLink="true">http://www.dslreports.com/forum/remark,17324726</guid>
<pubDate>Wed, 22 Nov 2006 16:13:59 EDT</pubDate>
</item>

</channel>
</rss>
