Conection to server

Discussions about CSEntry
Post Reply
Mariovaisman
Posts: 98
Joined: February 11th, 2013, 8:26 am

Conection to server

Post by Mariovaisman » September 16th, 2019, 1:54 pm

Hello,

About conection to FTP servers, when it is connecting, the screen shows the URL or IP address of the server, included the port. This information as it is shown, permits people to know where is located the server, and which is the port to access, it can cause security issues. Would be important not to show it, or at least have a mask or description in the SyncConnect function to avoid to show the real information, replacing it by that mask or description during the connection.

Thanks

Mario Vaisman

aaronw
Posts: 208
Joined: June 9th, 2016, 9:38 am
Location: Washington, DC

Re: Conection to server

Post by aaronw » September 17th, 2019, 5:00 pm

I consider the URL and IP address as public, so i don't consider this a security risk. However, I'll admit I'd probably not want to advertise the URL or IP address. I'll mention this to the team.

Just to say a bit more about security. A port scan will show which ports are open. Additionally, if we are referring to ftp and not ftps then all data is sent unencrypted which includes the username, password, port, and data.

Post Reply