[NEWSboard IBMi Forum]
Seite 1 von 2 1 2 Letzte

Hybrid View

  1. #1
    Registriert seit
    Apr 2004
    Beiträge
    31
    Hallo,

    ich habe den Job gefunden und den Zugriff rausgenommen.
    Die Methode mit Joblog, Netstat und Auditjournal finde ich persönlich nicht umbedingt elegant.
    Gibt es nicht eine andere Methode wie ich auf der AS/400 rausgehende FTP-Zugriffe identifizieren kann ?

    Gruß
    Kai

  2. #2
    Registriert seit
    Feb 2001
    Beiträge
    20.965
    Nur dann, wenn der FTP-Zugriff und damit das Programm aktiv ist !

    Ansonsten, alle Sourcen scannen auf FTP (über PDM) und prüfen, ob der noch gilt.

    Anständig dokumentieren, was auf dem System wann und wo läuft und von wem gestartet oder beendet werden kann oder wird .... usw. usw. usw......
    Dienstleistungen? Die gibt es hier: http://www.fuerchau.de
    Das Excel-AddIn: https://www.ftsolutions.de/index.php/downloads
    BI? Da war doch noch was: http://www.ftsolutions.de

  3. #3
    Registriert seit
    May 2002
    Beiträge
    2.645

    Tool zur Überwachung

    Hallo Kai,
    es gibt natürlich auch fertige Software:

    New iSeries Utility Addresses FTP Security
    by Alex Woodie
    The iSeries is recognized as one of the most secure servers available on the commercial market today. Its object-oriented design is virtually immune to today's viruses, and its five levels of built-in security gives systems administrators a great deal of control over which functions are available to various classes of users.
    However robust iSeries security is, the OS/400 platform was conceived long before today's Internet protocols were in widespread use. Without properly securing TCP/IP, FTP, and other network access points, your AS/400 or iSeries could be left as vulnerable as that Windows NT server down the hall.
    Shield Advanced Solutions has just started shipping a new utility that addresses unauthorized FTP access. FTP Manager/400 Version 1.0 allows systems administrators to control which users are allowed to transfer files to and from AS/400 or iSeries servers.
    FTP Manager/400 uses OS/400 exit points to capture and log all incoming and outgoing FTP requests, the company says. If a user fails to provide the correct password to access an FTP function, FTP Manager/400 automatically sends a message to QSYSOPR, the system administrator, alerting the administrator to take action.
    The utility logs all FTP access requests in real-time as message queues, database files, or Integrate File System files, depending on preferences and needs. Shield provides several levels of logging to address the iSeries shop's' disk management needs, the Toronto, Ontario, company says.
    FTP Manager/400 can also be configured to allow anonymous users to access the file transfer function, although this function can be removed to increase security if required, the company says.
    FTP Manager/400 costs between $1,100 and $6,500, depending on the size of the AS/400 or iSeries processor. For more information, visit Shield's Web site, at www.shield.on.ca.

  4. #4
    Registriert seit
    May 2002
    Beiträge
    2.645

    IBM Tool

    Hallo Kai,
    es gibt auch noch ein Tool von der IBM:
    CONTROLLING FTP SECURITY WITH EXIT PROGRAMS -- PART 2
    Boy, just when I think I've published the definitive list of FTP exit
    program resources, a helpful reader reminds me of another. The tool I
    omitted is the free Secured TCP Utility (SECTCP), which was written by
    IBMer Giovanni Perotti and is available at
    http://www-922.ibm.com/easy400p/downloads.html*. The utility enables
    you to secure FTP, WSG, and TELNET servers, log FTP, WSG, and TELNET
    activity, and display HTTP, FTP, WSG, and TELNET daily logs. Another
    downloadable utility, WSECTCP, provides a Web browser front-end to
    SECTCP. Both utilities require OS/400 V4R4 or greater.

    Thanks to Luis Rodrguez for the above tip.

  5. #5
    Registriert seit
    Mar 2002
    Beiträge
    5.416
    Hallo,

    Audit Journal ist unverzichtbar (obwohl es kaum jemand nutzt), wenn man mitgkriegen will, wenn jemand anfängt zu bohren. Alle Tools sind in den Wind geschossen, wenn jemand einen Weg drumherum sucht. Wenns da eine Automatik gäbe, dann gäbe es manche Probleme nicht.

    mfg

    Dieter Bender

    Zitat Zitat von kai
    Hallo,

    ich habe den Job gefunden und den Zugriff rausgenommen.
    Die Methode mit Joblog, Netstat und Auditjournal finde ich persönlich nicht umbedingt elegant.
    Gibt es nicht eine andere Methode wie ich auf der AS/400 rausgehende FTP-Zugriffe identifizieren kann ?

    Gruß
    Kai
    AS400 Freeware
    http://www.bender-dv.de
    Mit embedded SQL in RPG auf Datenbanken von ADABAS bis XBASE zugreifen
    http://sourceforge.net/projects/appserver4rpg/

  6. #6
    Registriert seit
    May 2002
    Beiträge
    2.645

    Sicherheit

    Hallo Kai,
    es gibt noch einen Sicherheitstip:

    If the QMAXSGNACN system value is set to 1, the QMAXSIGN system value applies to TELNET but not to FTP. If QMAXSGNACN is set to 2 or 3(values which disable the profile if the maximum sign on count is reached), FTP logon attempts are counted. In this case, a hacker can mount "denial of service" attack through FTP by repeatedly attempting to log on with an incorrect password until the user profile is disabled. For each unsuccessful attempt, the system writes a message CPF2234 to the QHST log. You can write a program to monitor the QHST log for message. If the program detects repeated attempts, it can end the FTP servers.

  7. #7
    Registriert seit
    Feb 2001
    Beiträge
    20.965
    Das betrifft wohl eher alles Incoming FTP !
    Wie siehts (wie in diesem Fall) mit Outgoing FTP aus ?
    Warum sollte die AS/400 da was aufzeichnen, wenn ein Programm wie FTP sich nicht am Windows-Server anmelden kann ?
    Wenn das Programm selber keine Nachricht erzeugt, dann föhliches Weitersuchen.
    Dienstleistungen? Die gibt es hier: http://www.fuerchau.de
    Das Excel-AddIn: https://www.ftsolutions.de/index.php/downloads
    BI? Da war doch noch was: http://www.ftsolutions.de

  8. #8
    Registriert seit
    Mar 2002
    Beiträge
    5.416
    @Baldur: da ist was wahres dran, obwohl das ja eigentlich ein security event darstellt und wenn ftp das als solches kennt, dann würde ich von audit journal schon erwarten das da zu finden.
    Ansonsten müsste man mal prüfen, ob man das auf einer Firewall mit entsprechender Protokollierung hinbekommt (wobei die gegen adress spoofing auch wenig ausrichten kann.

    Dieter

    Zitat Zitat von Fuerchau
    Das betrifft wohl eher alles Incoming FTP !
    Wie siehts (wie in diesem Fall) mit Outgoing FTP aus ?
    Warum sollte die AS/400 da was aufzeichnen, wenn ein Programm wie FTP sich nicht am Windows-Server anmelden kann ?
    Wenn das Programm selber keine Nachricht erzeugt, dann föhliches Weitersuchen.
    AS400 Freeware
    http://www.bender-dv.de
    Mit embedded SQL in RPG auf Datenbanken von ADABAS bis XBASE zugreifen
    http://sourceforge.net/projects/appserver4rpg/

  9. #9
    Registriert seit
    Jun 2001
    Beiträge
    727
    Ist doch oben schon angesprochen worden.

    Die Server Exit points (WRKREGINF) lassen es bei ftp zu sowohl Client (ausgehend) als auch Server (ankommend) Requests zu protokollieren/abzuweisen.

    Die Mühe ein kleines Programm zum schreiben und als ftp-exit-programm zu registrieren sollte man sich gönnen, wenn man nicht eine professionelle Software (z.B. PCSCCC/400, Penatsafe etc.) erwerben will.
    Bsp. gibt es genügend, auch im Infocenter.

  10. #10
    Registriert seit
    Apr 2004
    Beiträge
    31
    Das PCSACC/400 auch ausgehende FTP-Verbindungen mitschreibt bzw. blockt ist mir eigentlich neu. Ich kann einem User die Berechtigung geben das er mit FTP arbeiten darf mehr aber auch nicht. Oder gibt es da jetzt Neuerungen?

    Gruß,
    Kai

  11. #11
    Registriert seit
    Feb 2001
    Beiträge
    20.965
    Ich kann damit nur prüfen, ob FTP erlaubt/nicht erlaubt ist.
    Was innerhalb von FTP passiert, wird nur in den Log's (STDOUT von FTP) protokolliert.
    Vielleicht sollte man diese in eine OUTQ ausgeben.

    Wird für einen erlaubten User (bei PCSACC/400) aber nichts mehr protokolliert, hilft mir das nun wahrlich nicht besonders.
    Dienstleistungen? Die gibt es hier: http://www.fuerchau.de
    Das Excel-AddIn: https://www.ftsolutions.de/index.php/downloads
    BI? Da war doch noch was: http://www.ftsolutions.de

  12. #12
    Registriert seit
    Mar 2002
    Beiträge
    5.416
    Hallo,

    wenn ich das in der FTP reference richtig verstanden habe, wird auch vom FTP Client ein exit gefeuert, das Problem ist aber da, dass der vor der Ausführung anspringt und nicht danach. Mit anderen Worten, das hilft nix: ich bekomme zwar mit, wenn jemand einen logon an einem anderen FTP Server versucht, aber eben nicht was daraus geworden ist.

    mfg

    Dieter Bender

    Zitat Zitat von Fuerchau
    Ich kann damit nur prüfen, ob FTP erlaubt/nicht erlaubt ist.
    Was innerhalb von FTP passiert, wird nur in den Log's (STDOUT von FTP) protokolliert.
    Vielleicht sollte man diese in eine OUTQ ausgeben.

    Wird für einen erlaubten User (bei PCSACC/400) aber nichts mehr protokolliert, hilft mir das nun wahrlich nicht besonders.
    AS400 Freeware
    http://www.bender-dv.de
    Mit embedded SQL in RPG auf Datenbanken von ADABAS bis XBASE zugreifen
    http://sourceforge.net/projects/appserver4rpg/

Similar Threads

  1. Daten perr FTP ins IFS
    By malzusrex in forum IBM i Hauptforum
    Antworten: 3
    Letzter Beitrag: 05-12-06, 13:38
  2. Ftp put hängt sich auf
    By TARASIK in forum IBM i Hauptforum
    Antworten: 3
    Letzter Beitrag: 21-11-06, 16:18
  3. FTP
    By KM in forum IBM i Hauptforum
    Antworten: 4
    Letzter Beitrag: 28-08-06, 13:50
  4. Savf File per FTP
    By wuwu in forum IBM i Hauptforum
    Antworten: 5
    Letzter Beitrag: 18-08-06, 08:09
  5. FTP von V5R3M0 nach V5R4M0
    By Frank.Sobanek in forum IBM i Hauptforum
    Antworten: 5
    Letzter Beitrag: 22-06-06, 20:22

Berechtigungen

  • Neue Themen erstellen: Nein
  • Themen beantworten: Nein
  • You may not post attachments
  • You may not edit your posts
  •