I don't think I would do it but it isn't entirely crazy. I assume you are reverse proxying 20/21 to the server?
 
The main thing I see wrong would be if someone knows one of your internal userids and assuming you have a lockout policy, she could do a D.O.S. on that user by sending bad passwords for that account. Alternatively, it is a vector in to try and hack passwords overall. Also if someone somehow compromises the machine with an FTP overflow exploit of some sort, they then have control of a machine inside your firewall and a part of your forest. At the very least they could possibly work out a way to enumerate user account information from the entire forest and such.
 
  joe


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Noah Eiger
Sent: Friday, January 28, 2005 6:11 PM
To: [email protected]
Subject: [ActiveDir] FTP Server In or Out

Hello:

 

Is it crazy to place a publicly accessible FTP server 1) inside the firewall and 2) on a domain? We want to control domain users’ access to certain directories as well as partners connecting from the outside. Only one directory would be available to the world and then as read only.

 

Thanks.

 

-- nme

 

Reply via email to