News & Information for Technology Purchasers
NewsFactor Network Sites:   NewsFactor.com Security CRM Business Sci-Tech Newsletters XML/RSS Feed  
   
Home Enterprise I.T. Hardware Software Communications More Topics...
Software
Average Rating:
Rate this article:  
FTP Sites Vulnerable to Data Breaches FTP Sites Vulnerable to Data Breaches
By Peter Piazza
April 2, 2008 7:23AM

    Bookmark and Share
Tumbleweed, a vendor of content-security solutions, is debuting the freeware FTP Analyzer, which looks specifically for FTP traffic and provides a brief PDF summary of what it's seen, including user names, passwords and filenames. More sophisticated tools for managed file transfers will be rolled out later this year.
 

Advertisement

What do the U.S. Army Corps of Engineers and video-game giant Sega have in common? The answer is that both exposed sensitive data Relevant Products/Services via their File Transfer Protocol (FTP) sites. While the impact on Sega was only to force the company to release information on a new game earlier than it wanted to, in the former case it could have cost the lives of soldiers in Iraq.

FTP may be a dinosaur these days, but it's being used -- or, perhaps, misused -- regularly by employees who are simply trying to do their jobs, but who lack the adequate tools, according to John Thielens, vice president of technology for Tumbleweed, a vendor of content-security Relevant Products/Services solutions.

Employees Must Fend for Themselves

"When, for whatever reason, employees can't use e-mail -- the typical problem we have today is multimedia attachments where e-mail's not going to work -- they're looking for another solution," Thielens told us. Finding a solution, however, is often left to the user. Thielens noted that one survey showed 42 percent of companies don't tell employees what to do when that situation occurs. What happens then? "People make things up," he said.

FTP is often the solution employees come up with. It's ubiquitous, built into Web browsers so that users don't always even realize they're working with it. But Thielens noted that FTP is often left unsecured, with anonymous access allowed. That's not only a problem that can result in leaking important information to a competitor (or, as in the case of the Army Corps of Engineers situation, to the press). It means there's no audit trail, which can be particularly serious if the company is subject to disclosure laws.

All that's known, Thielens said, is that somebody accessed the site and took the information -- but there's no way to tell who.

Freeware Analysis Tool

Tumbleweed is debuting a freeware program at the upcoming RSA Conference called FTP Analyzer. "What we're trying to do with FTP Analyzer is raise awareness of the use of FTP because it's so ubiquitous," Thielens said. "It's not impossible to use FTP securely, but typically it isn't used safely."

FTP Analyzer is a simple-to-use tool that watches network traffic, looking specifically for FTP traffic. When it sees that traffic, it performs some analysis and provides a brief PDF summary of what it's seen. The product will note user names and passwords that passed by in the clear, as well as filenames.

The tool doesn't go beyond highlighting the extent of FTP usage on a network, Thielens said, but later this year Tumbleweed will roll out more sophisticated tools that will allow users to engage in managed file transfers from within the e-mail environment, with all necessary controls and filters.

In the meantime, good practices and common sense can help prevent problems. "This would include making sure that you're not using anonymous access or some other kind of public access," as well as staying away from shared accounts where credentials can be swapped, Thielens said. He also recommends implementing "file-purging procedures on FTP and other file servers, so even if data is sitting there, it's there for a day or a week, but not forever."

Finally, Thielens advises, "Implement some sort of user ID scrubbing, so that accounts that are disused or eliminated no longer have access."
 

Advertisement


Advertisement


 Software
1.   FAA Glitch Causes Air Travel Delays
2.   Call of Duty Is Setting Records
3.   MS Told To Stop Some Windows Sales
4.   Peer-to-Peer Software Ban Sought
5.   Better Maps, Made by Volunteers


advertisement
Windows 7: More Secure, More FunWindows 7: More Secure, More Fun
New OS can make users' lives easier.
Average Rating:
FAA Glitch Causes Air Travel DelaysFAA Glitch Causes Air Travel Delays
Computer software malfunction cited.
Average Rating:
Better Maps, Made by VolunteersBetter Maps, Made by Volunteers
Companies rely on locals with GPS.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Enterprise Hardware

  Go Green with IBM Blade Center
  

Network Security Spotlight
House Lawmakers Push Ban on Peer-to-Peer Software
Stung by an embarrassing electronic leak revealing ethics investigations into dozens of lawmakers, Congress moved to prohibit federal employees from using the file-sharing software blamed for the disclosure.
 
GAO: Los Alamos Computer Security Has Weaknesses
Security weaknesses uncovered in Los Alamos National Laboratory's computer network increase the risk of a classified-information breach, says the Government Accountability Office.
 
Computer Security Firm Fortinet Plans IPO This Week
Fortinet plans to go public in an initial public offering, giving investors a chance to tap a network security provider with sales that are expected to grow. The IPO could be valued at $137.5 million or more.
 

Enterprise Technology Spotlight
Flat Shipments Hurt Dell Despite Increased Earnings
Dell's earnings are up and expectations are solid, but the company's stock still took a hit after analysts signaled the company isn't playing a key role in the PC market recovery.
 
Smartphones: A Bigger Target for Security Threats
Smartphones are increasingly prevalent and adept at handling more tasks, including trading stocks, paying bills, and buying stuff online. That makes them attractive to thieves and hackers.
 
FBI Says Hackers Targeting Law Firms, PR Companies
Hackers are targeting law firms and public relations companies with a sophisticated e-mail scheme that breaks into their computer networks to steal sensitive data, often linked to large corporate clients.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Hardware | Software | Communications | Network Security | Wireless Tech | Linux/Open Source
Apple/Macintosh | Microsoft/Windows | World Wide Web | Data Storage | E-Commerce | Personal Tech | Tech Trends | Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | Free Whitepapers | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2009 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo.