温馨提示:本站仅提供公开网络链接索引服务,不存储、不篡改任何第三方内容,所有内容版权归原作者所有
AI智能索引来源:http://www.ssh.com/academy/ssh/ftp/server
点击访问原文链接

FTP Server – Beware of Security Risks

FTP Server – Beware of Security Risks Skip to content Products Show submenu for Products Products PrivX Privileged Access and Secrets Management Privileged Access Management Secure Remote Access for OT SSH Key Manager Tectia Secure File Transfer SSH Server SSH Client SSH Server for z/OS Encryption NQX Quantum-Safe Encryption FQX File Encryptor SalaX Secure Collaboration Secure Mail Secure Messaging Solutions Show submenu for Solutions Solutions Zero Trust Zero Trust Secrets Management Secrets Management Just-in-Time / Ephemeral Access Just-in-Time / Ephemeral Access Vendor Remote Access Vendor Remote Access Operational Technology Operational Technology Audit and Compliance Audit and Compliance Quantum Readiness Quantum Readiness Identity Security Identity Security Secure Collaboration Secure Collaboration Cloud Access Management /Hybrid Cloud Cloud Access Management /Hybrid Cloud Secure File Transfer Secure File Transfer Resources Show submenu for Resources Resources Content Library Blog SSH Academy Press Releases Case Studies Report a Vulnerability Company Show submenu for Company Company About Us Partners Investors Careers Customer Support Products Show submenu for Products Products PrivX Privileged Access and Secrets Management Privileged Access Management Secure Remote Access for OT SSH Key Manager Tectia Secure File Transfer SSH Server SSH Client SSH Server for z/OS Encryption NQX Quantum-Safe Encryption FQX File Encryptor SalaX Secure Collaboration Secure Mail Secure Messaging Solutions Show submenu for Solutions Solutions Zero Trust Zero Trust Secrets Management Secrets Management Just-in-Time / Ephemeral Access Just-in-Time / Ephemeral Access Vendor Remote Access Vendor Remote Access Operational Technology Operational Technology Audit and Compliance Audit and Compliance Quantum Readiness Quantum Readiness Identity Security Identity Security Secure Collaboration Secure Collaboration Cloud Access Management /Hybrid Cloud Cloud Access Management /Hybrid Cloud Secure File Transfer Secure File Transfer Resources Show submenu for Resources Resources Content Library Blog SSH Academy Press Releases Case Studies Report a Vulnerability Company Show submenu for Company Company About Us Partners Investors Careers Customer Support Get in touch
FTP Server – Beware of Security Risks

An FTP server runs on a computer to provide basic, unencrypted file transfer capability for connecting users. It is most commonly used for anonymous FTP, basically providing public files to anyone.

FTP uses cleartext passwords for authentication. Password sniffing attacks collecting user names and passwords from the network were common already in the mid-1990s. The FTP protocol has been largely replaced by SFTP and SSH. Today, FTP should only be used on extreme legacy systems and for public access anonymous FTP. Even for anonymous public access, HTTPS and web servers have largely replaced FTP. Since FTP is unencrypted, man-in-the-middle attacks can and have been used to inject malware into software downloaded using FTP.

Contents Secure Alternative (SFTP) Implementations Secure Alternative (SFTP)

We strongly recommend switching away from FTP as soon as possible. It is seriously not secure. Secure File Transfer Protocol (SFTP) is the alternative the world has moved to. Practically all commercial file transfer tools now support SFTP. It is supported on all modern operating systems. It also makes configuring automation much easier and supports secure key-based authentication.

It is practically impossible to achieve regulatory compliance in regulated industries, such as financials or health care, when using FTP. Public companies are also required to protect financial data.

Consequently, the use of FTP should be restricted to totally closed and trusted environments and anonymous access.

Implementations

We do not recommend configuring FTP servers. However, if one is needed, all Unix and Linux systems come with built-in FTP servers. For Windows, FileZilla Server is a possible alternative.

We recommend using SFTP. OpenSSH is a free open source server for Unix/Linux, and comes standard with every modern Unix, Linux, and Mac system. Tectia SSH is a widely used server for Windows. It is commercially supported, with 24x7 support available. It is also available for z/OS.

Solutions Zero Trust Secrets Management Just-in-Time/ Ephemeral Access Vendor Remote Access Operational Technology Audit and Compliance Quantum Readiness Identity Security Cloud Access Management/Hybrid Cloud Secure Collaboration Secure File Transfer Industries Healthcare Government MSPs Products PrivX Privileged Access and Secrets Management Privileged Access Management (PAM) Secure Remote Access for OT SSH Key Management Encryption NQX Quantum-Safe Encryption FQX File Encryption Tectia Secure File Transfer SSH Server SSH Client SSH Server for z/OS SalaX Secure Collaboration Secure Mail Secure Messaging Company About Us Partners Investors Careers Resources Talk to a security expert Support Product documentation Contact Us

Privacy Policy  |  Terms and Conditions

2026 © Copyright SSH

Secure 365

FTP Server – Beware of Security Risks,AI智能索引,全网链接索引,智能导航,网页索引

    An FTP server is insecure. They transmit passwords an data in the clear. SFTP/SSH has become the standard replacement.