SlideShare ist ein Scribd-Unternehmen logo
1 von 3
Downloaden Sie, um offline zu lesen
SECURE FTP (SFTP) USING A SECURE FTP CLIENT
Secure FTP (SFTP) for fast easy file transfer is hard to beat. Basic FTP however is not secure and
all transmissions are in clear text. Before the widespread deployment of wifi, intercepting these data
packets required a determined hacker with the means to intercept this traffic between point A (e.g.
your computer) and point B (e.g. your hosting site). This is known as packet sniffing. The intercepted
packets of data are clearly readable. With wifi and hotspot access becoming ubiqutous, it’s now fairly
trivial for hackers to grab your data stream which could contain potentially sensitive information such
as your username and password.
The good news is that it’s easy to prevent this or at least make it more difficult by using secure FTP.
The following examples explain how to configure FileZilla and WinSCP as secure FTP clients
connecting to a shared account on Hostgator. Check with your web host for availability, ports and
possible cost. For example: secure FTP (SSH enabled) on a Hostgator shared account is free but on
LunarPages it costs $2/mth IF you’re on a server that supports SSH.
NOTE: If you have a HG VPS or dedicated server account, you can further enhance security by
using SSH Keys and disabling username and password authentication for your SSH connections.
Here is a tutorial that will step you through the
process: http://support.hostgator.com/articles/specialized-help/ssh-keys.
For this example we will configure a secure FileZilla site profile.
IMPORTANT: If you are on a shared account, you MUST use your cPanel user/password in order to
use SFTP otherwise you will have to use plain FTP. If you must grant FTP access then be sure to
set the Directory (cPanel>FTP accounts>Add FTP Account) path to ONLY the required domain
and/or folder to limit your exposure.
How To Configure FileZilla As A Secure FTP (Sftp) Client
Secure FTP (sftp) using SSH
Step 1: Enable SSH (secure shell)
Verify with your web hosting provider that SSH is enabled for the domain that you want to
connect to via SFTP. For Hostgator call support and they will enable SSH. If you have a
Hostgator shared hosting account with a primary and addon domains, enabling SSH on your
primary domain also enables SSH for your addon domains.
Confirm with support which port SFTP will be using. For Hostgator shared accounts this is port
2222. If you have a VPS or dedicated server this will be port 22, however you can and should
change the port to something less well known.
Step 2: Configure a secure FTP (SFTP) site profile
Open FileZilla and create a new site. Give your site a name.
For the Host field you can use either the ip address of your server or
your domain name.
Fill in the port with the port number you obtained from your webhost.
Change the Server Type to SFTP – SSH File Transfer Protocol.
Change the Logon Type to Normal.
Enter your cPanel username and password.
You can now click OK to save or Connect to connect to your site.
Test your connection and if successful any future connections through this site profile will be
encrypted.
For this example we will configure a secure WinSCP session profile.
How To Configure WinSCP As A Secure FTP Client
Secure FTP using SSH
Step 1: Enable SSH (secure shell)
Verify with your web hosting provider that SSH is enabled for the domain that you want to
connect to via SFTP. For Hostgator call support and they will enable SSH. If you have a
Hostgator shared hosting account with a primary and addon domains, enabling SSH on your
primary domain also enables SSH for your addon domains.
Confirm with support which port SFTP will be using. For Hostgator shared accounts this is port
2222. If you have a VPS or dedicated server this will be port 22, however you can and should
change the port to something less well known.
Step 2: Configure a secure FTP (SFTP) session profile
Open WinSCP and create a new session.
For the Host field you can use either the ip address of your server or
your domain name.
Fill in the port with the port number you obtained from your webhost.
Enter your cPanel username and password.
Make sure that the File Protocol is SFTP.
You can now click Save or Login to connect.
Use secure FTP (SFTP) for secure file transfers and you’ll sleep better knowing that you’ve taken
another step to protect your business.
Need Help With A Hacked Site? Go Here: Sucuri.net
Download this article, Secure FTP, in pdf format.

Weitere ähnliche Inhalte

Andere mochten auch

FTP Client and Server | Computer Science
FTP Client and Server | Computer ScienceFTP Client and Server | Computer Science
FTP Client and Server | Computer ScienceTransweb Global Inc
 
Cara Membangun FTP Server di Windows Server 2008
Cara Membangun FTP Server di Windows Server 2008Cara Membangun FTP Server di Windows Server 2008
Cara Membangun FTP Server di Windows Server 2008Muhamad Prasetyo
 
SSL Secure socket layer
SSL Secure socket layerSSL Secure socket layer
SSL Secure socket layerAhmed Elnaggar
 
Buku Konfigurasi Debian Server BLC Telkom by Aji Kamaludin
Buku Konfigurasi Debian Server BLC Telkom by Aji KamaludinBuku Konfigurasi Debian Server BLC Telkom by Aji Kamaludin
Buku Konfigurasi Debian Server BLC Telkom by Aji KamaludinSuro Dhemit
 
Ebook Konfigurasi Dasar Linux Debian 7.8
Ebook Konfigurasi Dasar Linux Debian 7.8Ebook Konfigurasi Dasar Linux Debian 7.8
Ebook Konfigurasi Dasar Linux Debian 7.8Walid Umar
 
Introduction to Secure Sockets Layer
Introduction to Secure Sockets LayerIntroduction to Secure Sockets Layer
Introduction to Secure Sockets LayerNascenia IT
 

Andere mochten auch (10)

FTP Client and Server | Computer Science
FTP Client and Server | Computer ScienceFTP Client and Server | Computer Science
FTP Client and Server | Computer Science
 
SSL/TLS
SSL/TLSSSL/TLS
SSL/TLS
 
Cara Membangun FTP Server di Windows Server 2008
Cara Membangun FTP Server di Windows Server 2008Cara Membangun FTP Server di Windows Server 2008
Cara Membangun FTP Server di Windows Server 2008
 
SSL Secure socket layer
SSL Secure socket layerSSL Secure socket layer
SSL Secure socket layer
 
Buku Konfigurasi Debian Server BLC Telkom by Aji Kamaludin
Buku Konfigurasi Debian Server BLC Telkom by Aji KamaludinBuku Konfigurasi Debian Server BLC Telkom by Aji Kamaludin
Buku Konfigurasi Debian Server BLC Telkom by Aji Kamaludin
 
Ftp server
Ftp serverFtp server
Ftp server
 
Ebook Konfigurasi Dasar Linux Debian 7.8
Ebook Konfigurasi Dasar Linux Debian 7.8Ebook Konfigurasi Dasar Linux Debian 7.8
Ebook Konfigurasi Dasar Linux Debian 7.8
 
Http Vs Https .
Http Vs Https . Http Vs Https .
Http Vs Https .
 
Introduction to Secure Sockets Layer
Introduction to Secure Sockets LayerIntroduction to Secure Sockets Layer
Introduction to Secure Sockets Layer
 
Xampp installation
Xampp installation Xampp installation
Xampp installation
 

Kürzlich hochgeladen

DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDropbox
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusZilliz
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...DianaGray10
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)Samir Dash
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWERMadyBayot
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontologyjohnbeverley2021
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Orbitshub
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Zilliz
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native ApplicationsWSO2
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyKhushali Kathiriya
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMKumar Satyam
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdfSandro Moreira
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistandanishmna97
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...apidays
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Victor Rentea
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobeapidays
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...apidays
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKJago de Vreede
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FMESafe Software
 

Kürzlich hochgeladen (20)

DBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor PresentationDBX First Quarter 2024 Investor Presentation
DBX First Quarter 2024 Investor Presentation
 
Exploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with MilvusExploring Multimodal Embeddings with Milvus
Exploring Multimodal Embeddings with Milvus
 
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
Connector Corner: Accelerate revenue generation using UiPath API-centric busi...
 
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
AI+A11Y 11MAY2024 HYDERBAD GAAD 2024 - HelloA11Y (11 May 2024)
 
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWEREMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
EMPOWERMENT TECHNOLOGY GRADE 11 QUARTER 2 REVIEWER
 
Six Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal OntologySix Myths about Ontologies: The Basics of Formal Ontology
Six Myths about Ontologies: The Basics of Formal Ontology
 
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
Navigating the Deluge_ Dubai Floods and the Resilience of Dubai International...
 
Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)Introduction to Multilingual Retrieval Augmented Generation (RAG)
Introduction to Multilingual Retrieval Augmented Generation (RAG)
 
Architecting Cloud Native Applications
Architecting Cloud Native ApplicationsArchitecting Cloud Native Applications
Architecting Cloud Native Applications
 
Artificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : UncertaintyArtificial Intelligence Chap.5 : Uncertainty
Artificial Intelligence Chap.5 : Uncertainty
 
Introduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDMIntroduction to use of FHIR Documents in ABDM
Introduction to use of FHIR Documents in ABDM
 
[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf[BuildWithAI] Introduction to Gemini.pdf
[BuildWithAI] Introduction to Gemini.pdf
 
Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..Understanding the FAA Part 107 License ..
Understanding the FAA Part 107 License ..
 
CNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In PakistanCNIC Information System with Pakdata Cf In Pakistan
CNIC Information System with Pakdata Cf In Pakistan
 
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
Apidays New York 2024 - APIs in 2030: The Risk of Technological Sleepwalk by ...
 
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
Modular Monolith - a Practical Alternative to Microservices @ Devoxx UK 2024
 
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, AdobeApidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
Apidays New York 2024 - Scaling API-first by Ian Reasor and Radu Cotescu, Adobe
 
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
Apidays New York 2024 - Accelerating FinTech Innovation by Vasa Krishnan, Fin...
 
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUKSpring Boot vs Quarkus the ultimate battle - DevoxxUK
Spring Boot vs Quarkus the ultimate battle - DevoxxUK
 
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers:  A Deep Dive into Serverless Spatial Data and FMECloud Frontiers:  A Deep Dive into Serverless Spatial Data and FME
Cloud Frontiers: A Deep Dive into Serverless Spatial Data and FME
 

Secure FTP (SFTP) Using a Secure FTP Client

  • 1. SECURE FTP (SFTP) USING A SECURE FTP CLIENT Secure FTP (SFTP) for fast easy file transfer is hard to beat. Basic FTP however is not secure and all transmissions are in clear text. Before the widespread deployment of wifi, intercepting these data packets required a determined hacker with the means to intercept this traffic between point A (e.g. your computer) and point B (e.g. your hosting site). This is known as packet sniffing. The intercepted packets of data are clearly readable. With wifi and hotspot access becoming ubiqutous, it’s now fairly trivial for hackers to grab your data stream which could contain potentially sensitive information such as your username and password. The good news is that it’s easy to prevent this or at least make it more difficult by using secure FTP. The following examples explain how to configure FileZilla and WinSCP as secure FTP clients connecting to a shared account on Hostgator. Check with your web host for availability, ports and possible cost. For example: secure FTP (SSH enabled) on a Hostgator shared account is free but on LunarPages it costs $2/mth IF you’re on a server that supports SSH. NOTE: If you have a HG VPS or dedicated server account, you can further enhance security by using SSH Keys and disabling username and password authentication for your SSH connections. Here is a tutorial that will step you through the process: http://support.hostgator.com/articles/specialized-help/ssh-keys. For this example we will configure a secure FileZilla site profile. IMPORTANT: If you are on a shared account, you MUST use your cPanel user/password in order to use SFTP otherwise you will have to use plain FTP. If you must grant FTP access then be sure to set the Directory (cPanel>FTP accounts>Add FTP Account) path to ONLY the required domain and/or folder to limit your exposure. How To Configure FileZilla As A Secure FTP (Sftp) Client Secure FTP (sftp) using SSH Step 1: Enable SSH (secure shell) Verify with your web hosting provider that SSH is enabled for the domain that you want to connect to via SFTP. For Hostgator call support and they will enable SSH. If you have a Hostgator shared hosting account with a primary and addon domains, enabling SSH on your primary domain also enables SSH for your addon domains. Confirm with support which port SFTP will be using. For Hostgator shared accounts this is port 2222. If you have a VPS or dedicated server this will be port 22, however you can and should change the port to something less well known. Step 2: Configure a secure FTP (SFTP) site profile Open FileZilla and create a new site. Give your site a name. For the Host field you can use either the ip address of your server or your domain name. Fill in the port with the port number you obtained from your webhost. Change the Server Type to SFTP – SSH File Transfer Protocol. Change the Logon Type to Normal. Enter your cPanel username and password. You can now click OK to save or Connect to connect to your site. Test your connection and if successful any future connections through this site profile will be encrypted.
  • 2. For this example we will configure a secure WinSCP session profile. How To Configure WinSCP As A Secure FTP Client Secure FTP using SSH Step 1: Enable SSH (secure shell) Verify with your web hosting provider that SSH is enabled for the domain that you want to connect to via SFTP. For Hostgator call support and they will enable SSH. If you have a Hostgator shared hosting account with a primary and addon domains, enabling SSH on your primary domain also enables SSH for your addon domains. Confirm with support which port SFTP will be using. For Hostgator shared accounts this is port 2222. If you have a VPS or dedicated server this will be port 22, however you can and should change the port to something less well known. Step 2: Configure a secure FTP (SFTP) session profile Open WinSCP and create a new session. For the Host field you can use either the ip address of your server or your domain name. Fill in the port with the port number you obtained from your webhost. Enter your cPanel username and password. Make sure that the File Protocol is SFTP. You can now click Save or Login to connect.
  • 3. Use secure FTP (SFTP) for secure file transfers and you’ll sleep better knowing that you’ve taken another step to protect your business. Need Help With A Hacked Site? Go Here: Sucuri.net Download this article, Secure FTP, in pdf format.