General discussion
January 16, 2002 at 11:51 PM
rabbit_runner

FTP anonomyous Login

by rabbit_runner . Updated 24 years, 7 months ago

We have an NT 4.0 FTP server (sp6a) on a DMZ in our Sonicwall Firewall. The server has a public IP address and is not connected to our LAN. The ONLY use for this server is for FTP, Nothing else. Due to the nature of the services we provide for our customers, we need to allow Anonomyous Login to this FTP server. WWW is not enabled. McAfee is installed and we have the current DAT files. This server has two hard drives. Only one is used at any time. The second drive is a Ghost of the original install. The purpose is, if the server were to be attacked, hacked, or get a virus, we can switch to the other drive and do a ghost to correct the problem.

However, here is our issue, We are continually being hacked. It is happening every night. The hackers are leaving folders, files, and other junk on the site. Things such as COM1, LPT, (.). We know how to delete these folders but the hackers are returnning each night. Our customers are around the world and need to have access to this FTP server to put files that we can process the next business day. We are not concerned about them getting to our LAN, but they do use this server to do other attacks to other servers on the internet. Our server is being used as a stage for other attacks on the internet.

My question is this.. Is there any way we can configure, add other software, or adjustments to prevent this problem from happening?

Any help or advice would be appreciated. Thanks in advance.

This discussion is locked

All Comments