1847176 Members
5433 Online
110263 Solutions
New Discussion

Re: tftp security issues

 
Rajasekhar Raman
Frequent Advisor

tftp security issues

Are there any known security risks with tftp. Is it recommended that this service be disabled to have a more secure environment.

Also, does swinstall use tftp to do the remote installations ??

Thanks for you input.

-Shekar Raman
2 REPLIES 2
Donald Kok
Respected Contributor

Re: tftp security issues

Hi Shekar,
Yes tftp is unsecure, and hardly used these days. It is used by ignite to make and perform a net recovery. It is also used by omniback to push an agent. It is used by X-terminals, like Envizex. That's about it AFAIK. normally you can disable the service.

I think swinstall uses nfs as the network protocol , but I am not 100% sure.

Greetzz
Donald
My systems are 100% Murphy Compliant. Guaranteed!!!
Sridhar Bhaskarla
Honored Contributor

Re: tftp security issues

Hi Shekar,

tftp is unsecured in the sense it does not prompt for the passwords. So, depending on the tftp server configuration and the permissions on the server, there is a good chance that it can be a target of attack.

One other thing is that it does not encrypt the communication.

swinstall does not use tftp for sure for remote installations. I believe, it uses DCE/RPC.

-Sri
You may be disappointed if you fail, but you are doomed if you don't try