Inside the FTP and file-transfer review
File-transfer services are a frequent weak point: they are often left running from an old setup, exposed to the internet and protected only by a password. The audit reviews your FTP and file-transfer services.
We look at things such as:
- Whether transfers and logins are encrypted or sent in plain text where they can be intercepted.
- Anonymous or overly permissive access.
- Weak permissions and access-control gaps around the files served.
- Whether the service needs to be exposed at all, or could be locked down or replaced.
An insecure file-transfer service is a common route both for stealing data and for uploading malicious files onto a server. The audit reports what is exposed and how to close it off.

0 comments
Sign in with your TDesk account to comment.