Great Circle Associates Firewalls
(April 1993)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Is there an FTP client that logs activity?
From: Marcus J Ranum <mjr @ TIS . COM>
Date: Thu, 15 Apr 93 15:31:06 EDT
To: breinhar @ srg . srg . af . mil, firewalls @ GreatCircle . COM

>Is there an ftp client that can replace the one that
>comes from SCO for SCO ODT 1.1/2.0 that will log
>the file transfers that people do?

	The one on gatekeeper.dec.com in pub/DEC does so, I believe. It
logs the GET/PUT commands users issue.

>The aim obviously is to keep tracking of files that
>are brought into the local network from the outside.
>This is in addition to manually screening code and
>virus checking binaries.

	The problem is that if I can FTP from the net, I can FTP the
sources for a client FTP and use my own, which does no logging.

	This problem you're dealing with is why I designed the FTP
applications gateway DEC (and its SEAL customers) use - the only way
to *really* know that you're getting an accurate picture of what is
going in or out via FTP is to interpose a block and have an application
gateway that logs traffic. The DEC FTP gateway also lets the firewall
manager select what to log, and gives the ability to block certain
commands directionally, depending on who is talking to whom.

	Virii are a whole 'nother, very, very tricky issue. With all
the zillions of ASCII encodings of binaries and with the ability to
Email stuff, it's almost impossible to prevent people from bringing
in virii, other than through educating them.

mjr.


Indexed By Date Previous: Is there an FTP client that logs activity?
From: Bob Reinhardt <breinhar @ srg . af . mil>
Next: Re: X traffic, academic environments
From: Mike Robitaille <miker @ jupiter . fuentez . com>
Indexed By Thread Previous: Is there an FTP client that logs activity?
From: Bob Reinhardt <breinhar @ srg . af . mil>
Next: Re: Is there an FTP client that logs activity?
From: bdboyle @ maverick1 . erenj . com (Bryan D. Boyle)

Google
 
Search Internet Search www.greatcircle.com