Help! Need to find alternative to unsecured FTP
Thread poster: OnePlanet

OnePlanet
Local time: 22:45
Member (2004)
Arabic to English
+ ...
Nov 17, 2004

Our company maintains an FTP server, which is used for our customers and vendors to upload several large files. The traffic is about 40 – 60 files per day, files ranging from 200 Kb to 30 MB per file. Frequently there will be one login and password for a specific job because multiple users need to access the same material.

The solution should have the following attributes:

1. Able to easily handle multiple files (20 – 30 files at a time)

2. Able to handle large file transfers

3. Multiple simultaneous user access with the same account

4. Easy administration – creation and deletion of user accounts with restricted access

We are concerned that someone might break into FTP site and use our server box as a jump-off point for malicious acts (spam, etc.). Is there a way we can be protected and still have a nimble and flexible file transfer system? Our customers and vendors change frequently, are not very computer literate and therefore we are not in position to equip them with any custom software (SFTP), nor teach them any special way of handling the site. Additionally, we need our project manager to be able to administer passwords and logins.

We have looked at some web-based solutions (phpAdmin and the like), but have found these too clumsy to handle the queues of files transferred back and forth between clients and vendors.

If anyone can think of some elegant solution to this essentially security related problem, I would be grateful.


Direct link Reply with quote
 

Robert Tucker
United Kingdom
Local time: 03:45
German to English
+ ...
HTTP Nov 17, 2004

I'm quite out of my depth here, but why not HTTP if, say, VSFTPD cannot provide the security you require ?

Sorry if this sounds a daft question/suggestion.

(Apache http server free Windows/Unix/Linux, vsftpd free Unix/Linux only)

[Edited at 2004-11-18 11:56]


Direct link Reply with quote
 
Pablo Roufogalis
Colombia
Local time: 22:45
English to Spanish
FirstClass Nov 17, 2004

Hello.

Check FirstClass at www.firstclass.com. It's a great product and probably what you need. Very easy to administer.

You can download a demo version for free (5 users, multiple logins from the same account). Hey, it may be all you need!

I resell it for the Venezuelan market. I can't sell it to you nor would I get any recognition or profit if you buy. My recommendation is sincere.

Best regards.


Direct link Reply with quote
 
Mathew Robinson
United Kingdom
Local time: 03:45
English
Bulletproof FTP Server Nov 18, 2004

We use Bulletproof FTP Server v2.3.1.26 for the exact same purpose.

It allows you to create group accounts as well as single accounts.

You can specify how many simultaneous connections are allowed per user account.

You can restrict user access to read/write.

You can specify accepted file types.

You can restrict user to specified directories.

You can limit connections to specific IP addresses.

You can block IP's

It works with PASV and PORT

It supports RESUME

We set ours up on a dedicated PC and ADSL line and it works great on WinXP with ICF enabled.

It is very reasonably priced compared to other brands and worth checking out. A 30 day trial version is available from their website... http://www.bpftpserver.com/


Direct link Reply with quote
 
timoke
Dutch to English
Http/web based solution Nov 18, 2004

Hi,

i have developed a http/web based solution for this problem.

Many translation agencies don't have their own ftp server and since the cost of hardware, software and licenses can be quite high, i have developed a custom solution.

I will explain the principle in short:

Instead of using ftp with a single user I use http with custom authentication, this has the advantage that a users can only see his own documents and not documents uploaded by others.

Users administration can be done web based by an administrator.

Behind the scenes the documents are stored in a secure (not directly via web accessible) folder so that downloading and uploading of documents can only be done via the dedicated pages (these pages handle all security issues).

The solution uses Microsoft's .NET technology (free) and sql server (license needed). You can host it on your own server or you can host it at a third party (www.brinkster.com for example offers 2GB of space for 20$/month), which makes it a very chaep and flexible alternative to maintaining your own ftp server.

Documents are organized by customer/freelancer and by project. For example: a customer can have 10 running projects and can upload the source files to a project and download the translated files from that project.

If this could solve your problem, please feel free to contact me for more information.

Regards,

timothy steleman
timothy.steleman@pandora.be


Direct link Reply with quote
 


To report site rules violations or get help, contact a site moderator:


You can also contact site staff by submitting a support request »

Help! Need to find alternative to unsecured FTP

Advanced search






Déjà Vu X3
Try it, Love it

Find out why Déjà Vu is today the most flexible, customizable and user-friendly tool on the market. See the brand new features in action: *Completely redesigned user interface *Live Preview *Inline spell checking *Inline

More info »
SDL MultiTerm 2017
Guarantee a unified, consistent and high-quality translation with terminology software by the industry leaders.

SDL MultiTerm 2017 allows translators to create one central location to store and manage multilingual terminology, and with SDL MultiTerm Extract 2017 you can automatically create term lists from your existing documentation to save time.

More info »



Forums
  • All of ProZ.com
  • Term search
  • Jobs
  • Forums
  • Multiple search