Discussion:
FXP on IIS 5.1....?
(too old to reply)
mars
2004-07-07 09:50:20 UTC
Permalink
Hi guys!! I'd like to enable FXP transfer on a FTP server with IIS 5.1
but I read that there could be some security problems (FTP bounce
attack)... I'm running it on WinXP Pro. what do you think about it?

I was also looking forward to upgrade from IIS 5.1 to IIS 6, what
pro/cons would I get? (difficulties in setting up?)

thank you!!!
Alun Jones [MSFT]
2004-07-08 20:47:12 UTC
Permalink
Post by mars
Hi guys!! I'd like to enable FXP transfer on a FTP server with IIS 5.1
but I read that there could be some security problems (FTP bounce
attack)... I'm running it on WinXP Pro. what do you think about it?
The article at http://support.microsoft.com/?id=247132 describes how to
enable this functionality on IIS version 4 and 5. As the notes suggest, and
the names of the registry variables underscore, this can be a security
problem. The bounce attack ("EnablePortAttack" registry setting) and data
port theft ("EnablePasvTheft") are documented in
http://www.ietf.org/rfc/rfc2577.txt - as you can see, these are general
problems with FTP and server-to-server transfers, which is why it's usually
suggested to disable server-to-server transfers,

Note that very few people will understand you when you talk about "FXP".
I'm really not quite sure where that term came from, but the FTP
documentation refers to it as "third party transfer", "server to server
transfer" or "proxy transfer". There are no official documents an FTP
developer could search for that describe this as "FXP". Searching on "FXP"
will likely lead you to documentation on Microsoft Visual FoxPro.
Post by mars
I was also looking forward to upgrade from IIS 5.1 to IIS 6, what
pro/cons would I get? (difficulties in setting up?)
Well, for a start you'd be switching from Windows XP to Windows 2003.
<http://support.microsoft.com/?id=224609> - Windows 2003 comes with a list
of improvements that would really be far too long to go into in a Usenet
posting.

Additional information on IIS 6.0, its technical overview, and a review of
security enhancements made, can be found at various pages under
http://support.microsoft.com/default.aspx?scid=fh;EN-US;iis60

Alun.
~~~~

Continue reading on narkive:
Search results for 'FXP on IIS 5.1....?' (Questions and Answers)
5
replies
outlook 2007 blocks my outgoing attachments?
started 2008-12-30 06:40:35 UTC
software
Loading...