Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

AppTheory specializes in solutions based on the DotNetNuke platform and has 2 employees on the DotNetNuke Core Team.
  Ads  
Aspose - The .NET & Java component publisher
 


  Sponsors  

Meet Our Sponsors

Red-Gate Software
MaximumASP
SourceGear - Tools for Developers
.: CounterSoft :.
telerik
ExactTarget email software solutions
 


DotNetNuke Forums
 
  Forum  General DotNetN...  Extend It! ( Pr...  FTP Deployment
Previous Previous
 
Next Next
New Post 8/19/2006 1:12 PM
User is offline Mark Stouffer
23 posts
10th Ranked


FTP Deployment 

I searched this but I suspect this may have been covered elsewhere, so I apoligize in advance.

What are the security risks of using the ftp deployment in the Visual Studio 2005 IDE? I want to develop and test on my home pc and then use the file copy to upload to my live production server. Can I just ftp directly to the IIS directory of the live site? I mean I know I can. That is what I do on the closed network at work. But what are the security risks of doing this on the wide blue www? Is my password and username interceptable since it is sent as clear text? Wouldn't that give sniffers the ability to hijack my whole site?

 
New Post 8/19/2006 7:16 PM
User is offline cathal connolly
2757 posts
www.cathal.co.uk
5th Ranked










Re: FTP Deployment 

yes, by default ftp username/passwords are sent in clear text, you can use secure-ftp instead if you like to stop anyone eavesdropping on you (http://en.wikipedia.org/wiki/File_Transfer_Protocol), but as typically the only people with sufficent access would be people on your own network (e.g. if you were on an office intranet), or your ISP, then realistically it's not much of a risk

Cathal

 
New Post 8/31/2006 1:52 PM
User is offline Mark Stouffer
23 posts
10th Ranked


Re: FTP Deployment 

I think I am not getting something. Please forgive my technotardation.

I am using it on the internet. Who... how is access limited to certain people if I am connecting to a server in Germany? You said 'as typically the only people with sufficient access would be people on your own network, or ISP". But I am sending my access credentials in clear text. I think I am concerned that they could gain 'sufficient access' by using a packet sniffer or something.

Is that how they do it? I send my log in credentials in clear text. They sniff all traffic and look for ftp login packets, identify the IP that I am loggin into. They basically use the masive processing and search power of modern computers to 'capture' my login info and then login pretending to be me. Something like that? I don't actually know what I'm talking about or all the mechanations of this process, but I understand it is something to avoid, no?

I will read the secure FTP info and try to set that up. I sincerely thank you, cathal, for the info and help.

 
Previous Previous
 
Next Next
  Forum  General DotNetN...  Extend It! ( Pr...  FTP Deployment
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


MaximumASP
MaximumASP provides a wide array of web hosting plans to fit any hosting need. We also provide software and services needed to keep it running optimally.
MaximumASP.com
Mad Development: dotnetnuke design and development
We are an expert Dotnetnuke shop specializing in developing solutions that merge the requirements of design and branding, content management, ecommerce, search engine optimization and business logic.
www.MadDevelopment.com
telerik
telerik r.a.d.controls suite is the most innovative and comprehensive toolset for ASP.NET development, tailored for seamless integration with the DotNetNuke project. This integrated collection of controls allows professionals to build web-solutions with the UI richness and responsiveness of desktop applications.
dnn.telerik.com

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP