News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Software
Average Rating:
Rate this article:  
FTP Sites Vulnerable to Data Breaches FTP Sites Vulnerable to Data Breaches
By Peter Piazza
April 2, 2008 7:23AM

    Bookmark and Share
Tumbleweed, a vendor of content-security solutions, is debuting the freeware FTP Analyzer, which looks specifically for FTP traffic and provides a brief PDF summary of what it's seen, including user names, passwords and filenames. More sophisticated tools for managed file transfers will be rolled out later this year.
 



What do the U.S. Army Corps of Engineers and video-game giant Sega have in common? The answer is that both exposed sensitive data Relevant Products/Services via their File Transfer Protocol (FTP) sites. While the impact on Sega was only to force the company to release information on a new game earlier than it wanted to, in the former case it could have cost the lives of soldiers in Iraq.

FTP may be a dinosaur these days, but it's being used -- or, perhaps, misused -- regularly by employees who are simply trying to do their jobs, but who lack the adequate tools, according to John Thielens, vice president of technology for Tumbleweed, a vendor of content-security solutions.

Employees Must Fend for Themselves

"When, for whatever reason, employees can't use e-mail -- the typical problem we have today is multimedia attachments where e-mail's not going to work -- they're looking for another solution," Thielens told us. Finding a solution, however, is often left to the user. Thielens noted that one survey showed 42 percent of companies don't tell employees what to do when that situation occurs. What happens then? "People make things up," he said.

FTP is often the solution employees come up with. It's ubiquitous, built into Web browsers so that users don't always even realize they're working with it. But Thielens noted that FTP is often left unsecured, with anonymous access allowed. That's not only a problem that can result in leaking important information to a competitor (or, as in the case of the Army Corps of Engineers situation, to the press). It means there's no audit trail, which can be particularly serious if the company is subject to disclosure laws.

All that's known, Thielens said, is that somebody accessed the site and took the information -- but there's no way to tell who.

Freeware Analysis Tool

Tumbleweed is debuting a freeware program at the upcoming RSA Conference called FTP Analyzer. "What we're trying to do with FTP Analyzer is raise awareness of the use of FTP because it's so ubiquitous," Thielens said. "It's not impossible to use FTP securely, but typically it isn't used safely."

FTP Analyzer is a simple-to-use tool that watches network Relevant Products/Services traffic, looking specifically for FTP traffic. When it sees that traffic, it performs some analysis and provides a brief PDF summary of what it's seen. The product will note user names and passwords that passed by in the clear, as well as filenames.

The tool doesn't go beyond highlighting the extent of FTP usage on a network, Thielens said, but later this year Tumbleweed will roll out more sophisticated tools that will allow users to engage in managed file transfers from within the e-mail environment, with all necessary controls and filters.

In the meantime, good practices and common sense can help prevent problems. "This would include making sure that you're not using anonymous access or some other kind of public access," as well as staying away from shared accounts where credentials can be swapped, Thielens said. He also recommends implementing "file-purging procedures on FTP and other file servers, so even if data is sitting there, it's there for a day or a week, but not forever."

Finally, Thielens advises, "Implement some sort of user ID scrubbing, so that accounts that are disused or eliminated no longer have access."
 

Tell Us What You Think
Your Comment:



Advertisement


 Software
1.   Tips for More Windows 7 Productivity
2.   MS: Russian Pirates Scamming Us
3.   Veteran SAP CEO Abruptly Resigns
4.   Mobile Phone Apps Gaining Ground
5.   Twitter Clients Save Time and Clicks


advertisement
Oracle, Adobe Patch VulnerabilitiesOracle, Adobe Patch Vulnerabilities
Microsoft's Patch Tuesday very light.
Average Rating:
Tips for More Windows 7 ProductivityTips for More Windows 7 Productivity
Win 7 is chock-full of unsung features.
Average Rating:
Veteran SAP CEO Abruptly ResignsVeteran SAP CEO Abruptly Resigns
Cofounder will guide new co-CEOs.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware Spotlight
Microsoft Says Battery Woes Not Caused By Windows 7
Battery problems on Windows 7 machines are not caused by the operating system. That's the position of Stephen Sinofsky, head of the Windows division, in a long posting on the Windows engineering blog.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
'Dead Simple, Dirt Cheap' JooJoo Tablet Shipping Soon
The JooJoo, a web-browsing tablet device that is the subject of a high-profile legal dispute, appears on track to reach buyers at the end of February, but the tablet scene has dramatically changed.
 

Enterprise Technology Spotlight
Google May Add Facebook, Twitter Links to Gmail
Google will reportedly roll more social-networking features into Gmail, the fastest-growing e-mail service. The new features could save users the trouble of switching to Facebook or Twitter.
 
IBM's New POWER7 Servers Save Energy with Big Loads
IBM has unveiled high-capacity servers that are the first to be based on its new, multi-core POWER7 chip. It said the new line is designed "to manage the most demanding emerging applications."
 
IBM Opens Eco-Friendly, Cloud-Focused Data Center
IBM has opened its latest data center in North Carolina. Big Blue said the $362 million facility in Research Triangle Park is designed to support cloud computing and other new computing models.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2010 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.