FTP Server--how are people finding me?
- Hipnotic_Tranz
- Almighty Member
- Posts: 3750
- Joined: Wed Nov 22, 2000 6:35 am
- Location: Indpls, IN
- Contact:
FTP Server--how are people finding me?
I'm running an FTP server for my own personal use (mainly so if I go to a friends house and forget a .cfg file or something, I can easily get it). I'm lookin' at the log and am seeing a bunch of IP's I don't recognize (not any of my friends IPs) so how are these people finding my IP? I have it password protected but people still try to guess it or log-in anonymously and it's just annoying. I don't even know how they are finding my FTP server. I mean, I know it's not hard to find my IP but how many people really sit around and try to http://ftp.xxx.xxx.xxx for every IP they come across?
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
<i>
My get up and go
must have got up and went.
</i>[/align]
- Busby
- Golden Member
- Posts: 1890
- Joined: Tue Nov 28, 2000 6:25 pm
- Location: Atlanta Area, GA, USA
- Contact:
Basically, as Pred said, people are scanning ports and finding an open port 21 (probably) and then trying to login. I say that you should change your port to a weird port that most people wouldn't scan by default.
<a href="mailto:busby1218@charter.net">
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
<img src="http://justinbusby.com:8080/signature.gif" border="0"></a>
- Hipnotic_Tranz
- Almighty Member
- Posts: 3750
- Joined: Wed Nov 22, 2000 6:35 am
- Location: Indpls, IN
- Contact:
-
NascarFool
- Posts: 3263
- Joined: Thu Nov 23, 2000 1:21 pm
- Hipnotic_Tranz
- Almighty Member
- Posts: 3750
- Joined: Wed Nov 22, 2000 6:35 am
- Location: Indpls, IN
- Contact:
-
NascarFool
- Posts: 3263
- Joined: Thu Nov 23, 2000 1:21 pm
- Hipnotic_Tranz
- Almighty Member
- Posts: 3750
- Joined: Wed Nov 22, 2000 6:35 am
- Location: Indpls, IN
- Contact:
-
TruckStuff
- Golden Member
- Posts: 1056
- Joined: Thu Feb 07, 2002 5:17 pm
- Location: Dallas, TX
Security through obscruity (i.e. changing ports for common services) is no security at all. Part of running an FTP server (or any server for that matter) that is connected to the internet is that people will find it and try to access it. That is why you have users, groups, etc. setup: to allow some people and deny others. While changing the port of the service may get you fewer "connection attempt from x.x.x.x" entires in your log files, it certainly will not prevent anyone from "finding" your server.
- Hipnotic_Tranz
- Almighty Member
- Posts: 3750
- Joined: Wed Nov 22, 2000 6:35 am
- Location: Indpls, IN
- Contact:
Thats all I'm looking for though. I got tired of so many anonymous people tryin' to get in. I have passwords on all my users/groups because this server is for me and my friends only. I mean, the login/password I made for my friends is very simple and some even guessed it, thats why I wanted to find out how these people were finding me and if there was a way to "hide" myself, so to speak.
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
<i>
My get up and go
must have got up and went.
</i>[/align]
-
TruckStuff
- Golden Member
- Posts: 1056
- Joined: Thu Feb 07, 2002 5:17 pm
- Location: Dallas, TX
If people are successfully guessing the passwords, you have another problem to worry about. Passwords that are easily guessed are extermely poor and defeat the entire purpose of having users and passwords. If someone can guess them correctly, you need to change them immediately. Passwords are your first line of defense and compromising them is how 95% of system breakins begin. Simply changing the port may keep the really stupid script kiddies out, but even a somewhat stupid script kiddie will get around that.
Besides, I like seeing all those access denied in my logs. Lets my know that my security measures are working the way they should.
Besides, I like seeing all those access denied in my logs. Lets my know that my security measures are working the way they should.
- Hipnotic_Tranz
- Almighty Member
- Posts: 3750
- Joined: Wed Nov 22, 2000 6:35 am
- Location: Indpls, IN
- Contact:
Well, the login/password for my friends group is very simple and I really didn't care that they cracked in (not at all surprised really). That group has no more access than to look at what I have and download it. They can't upload/rename/make directories/etc. I kept the login/password simple so my friends can remember it.
My account on the other hand has a fairly simple username but the password is one I doubt anybody could figure out. The only reason I set a username/password in my friends account in the first place was to keep these anonymous people away....then they started guessing and when they were finally getting in thats when I got fed up and was wondering how they found me in the first place.... ...thus my post began
Ever since my port change, I haven't seen one UIP (unidentified IP
) in my log, though.
My account on the other hand has a fairly simple username but the password is one I doubt anybody could figure out. The only reason I set a username/password in my friends account in the first place was to keep these anonymous people away....then they started guessing and when they were finally getting in thats when I got fed up and was wondering how they found me in the first place.... ...thus my post began
Ever since my port change, I haven't seen one UIP (unidentified IP
[align=center]<img src=http://i54.tinypic.com/j9tydf.gif>
<i>
My get up and go
must have got up and went.
</i>[/align]
<i>
My get up and go
must have got up and went.
</i>[/align]