Solved

DMZ Security Risk Questions

Posted on 2011-02-23
6
769 Views
Last Modified: 2013-12-02
I'm trying to determine if there are any weaknesses relating to an FTP server in our DMZ. Where would I start looking? I know this is a vague question, but I'm concerned about files containing sensitive data being stored on the server. Where would I start? Again, I know this is vague, but humor me. Thanks guys.
0
Comment
Question by:isaacr25
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 21

Expert Comment

by:Rick_O_Shay
ID: 34969373
I don't think you should put sensitive information on a server facing the outside where anyone can reach it.
0
 

Author Comment

by:isaacr25
ID: 34969866
Even in the DMZ? Can you give me some reasons why? I'm not saying I support where it is... I just want some further info on the topic.
0
 
LVL 16

Accepted Solution

by:
AlexPace earned 334 total points
ID: 34969874
FTP sends userids and passwords in plain text.  Your users will be tempted to use the same password for everything so this is dangerous if they also have a domain account.  Its better to use one of the encrypted versions like FTPS (ftp over ssl) or SFTP (based on ssh.)
0
Retailers - Is your network secure?

With the prevalence of social media & networking tools, for retailers, reputation is critical. Have you considered the impact your network security could have in your customer's experience? Learn more in our Retail Security Resource Kit Today!

 

Author Comment

by:isaacr25
ID: 34970838
Ok. So what about files that sit on the server (not necessarily being FTP's or SFTP'd)? How can those be at risk?
0
 
LVL 21

Assisted Solution

by:Rick_O_Shay
Rick_O_Shay earned 166 total points
ID: 34971769
By definition things in the DMZ are outward facing and can be seen by anyone outside.
That makes it susceptible to attempts to hack it.
Sensitive stuff should be on the inside and only accessible to legitimate users via secure connection like SSL or IPSEC.
0
 
LVL 16

Assisted Solution

by:AlexPace
AlexPace earned 334 total points
ID: 34971886
For the same reason you need to be careful to keep the OS patched on all your machines in the DMZ.  You can't just wait and do it every 6 months or whenever you get around to it.
0

Featured Post

Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Ready for our next Course of the Month? Here's what's on tap for June.
Email attacks are the most common methods for initiating ransomware and phishing scams. Attackers want you to open an infected attachment or click a malicious link, and unwittingly download malware to your machine. Here are 7 ways you can stay safe.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, just open a new email message. In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
With Secure Portal Encryption, the recipient is sent a link to their email address directing them to the email laundry delivery page. From there, the recipient will be required to enter a user name and password to enter the page. Once the recipient …

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question