Re: [Fedora] Re: Blocking SSH ... BUT...



On Tue, 18 Sep 2007 17:29:47 -0600
"Ashley M. Kirchner" <ashley@xxxxxxxxxx> wrote:

kalinix wrote:
But, since you are using ssh, I suggest start using also sftp for file
transfer: much more secure, encrypted, no plain text passwords and only
tcp port 22 opened in firewall.
I cannot enforce this on our clients. I have to allow for standard
FTP protocol. However your point is well taken. In a perfect world,
sure...

In which case I suspect you need to look hard at WebDAV and other https://
based transfer options before someone sniffs all the passwords and has a
party at your expense.

(WebDAV is the standard microsoft embraced, and so far hasn't extended ;)
but decided to call 'My Network Places' rather than WebDAV) and is built
into modern versions of their products as a network drive.

--
fedora-list mailing list
fedora-list@xxxxxxxxxx
To unsubscribe: https://www.redhat.com/mailman/listinfo/fedora-list



Relevant Pages

  • key_read: missing keytype
    ... I have an OpenSSH server v3.8 on a linux machine. ... My objective is to use pubkey authentication only, and NO passwords. ... I have several linux clients that can connect to the sshd without problem, ...
    (comp.security.ssh)
  • Re: building a server web FTP with apache
    ... SSH with chroot cages (plenty of Windows SCP/SFTP clients can support this). ... FTP(with all its poor security limitations, which make passwords vulnerable ... DAVExplorer used as a Java applet to make it entirely web form based. ...
    (comp.os.linux.security)
  • [NEWS] SAP R/3 Default Password Vulnerability
    ... As many ERP software packages SAP R/3 is capable of installing different ... Whereas the default passwords are normally changed in production clients, ... A typical SAP R/3 installation consists of at least 4 clients. ...
    (Securiteam)
  • Re: NIS setup
    ... I tried this a year ago without any success, ... back to passwords. ... Both Linux and Mac clients can use ... I've tried following the instructions of the Debian NIS HOWTO ...
    (Debian-User)
  • RE: Password complexity - improvement
    ... The default will enforce 3 of the following 4 properties - Uppercase, ... Enforcing passwords that MUST consist of uppercase letters, ...
    (Focus-Microsoft)