Anonymous FTP

Discussion in 'Security' started by wierdo, Dec 22, 2008.

  1. #1
    I was fixing my sites from getting hacked for the 4th - 5th time and remembered that I had turned Anonymous FTP on. I feel really stupid asking this, but I could get hacked with anonymous FTP on, right?
     
    wierdo, Dec 22, 2008 IP
  2. SSANZ

    SSANZ Peon

    Messages:
    861
    Likes Received:
    10
    Best Answers:
    0
    Trophy Points:
    0
    #2
    yes, your configuration files could have been downloaded by anonymous FTP.

    Also anonymous FTP allows users to upload malicious files allowing further access to be gained.
     
    SSANZ, Dec 24, 2008 IP
  3. wierdo

    wierdo Well-Known Member

    Messages:
    1,646
    Likes Received:
    45
    Best Answers:
    0
    Trophy Points:
    140
    #3
    Yeah, I thought this was why I was having so much trouble. Didn't remember I had turned it on for a long time. :eek:

    Thanks
     
    wierdo, Dec 26, 2008 IP
  4. Linked2K

    Linked2K Peon

    Messages:
    19
    Likes Received:
    0
    Best Answers:
    0
    Trophy Points:
    0
    #4
    That depens, if you lock anonymous ftp to a subdirectory with only read permissions, nothing is wrong. If they can access the entire disk read/write. You are fucked.
     
    Linked2K, Jan 18, 2009 IP
  5. grk519

    grk519 Peon

    Messages:
    293
    Likes Received:
    4
    Best Answers:
    0
    Trophy Points:
    0
    #5
    Also people scan for anonymous FTP sites to use as "dump sites" for illegal software such as warez or mp3 and then distribute this information over the internet. So you might have also been loosing bandwith here :>
     
    grk519, Jan 19, 2009 IP
  6. engineerroy2008

    engineerroy2008 Member

    Messages:
    192
    Likes Received:
    3
    Best Answers:
    0
    Trophy Points:
    33
    #6
    Disable anonymous ftp its good security measure to prevent attack like this, but also check other files for any injection or malwares
     
    engineerroy2008, Jan 25, 2009 IP