• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • Shield Delivers Monitoring Solution for FTP on IBM i

    June 19, 2024 Alex Woodie

    Shield Advanced Solutions last month delivered FT4i, a new utility that helps to secure File Transfer Protocol (FTP) activity on IBM i. The new tool not only controls who is allowed to use FTP, but also logs all FTP activity to uncover possibly criminal activity after the fact.

    FTP is one of the most heavily used Internet protocols in the world. Across every industry, organizations use FTP to send and receive what is likely petabytes worth of data every single day. If the Internet is a “super highway,” then FTP is the 20-lane workhorse of an Interstate freeway, facilitating information flow and commerce.

    But FTP also happens to have security vulnerabilities. The problem isn’t in the protocol itself, although best practices mandate that companies use encrypted forms of FTP, either SFTP (which uses SSH) or FTPS (which uses TLS/SSL). The problem lies in how organizations use FTP.

    According to Chris Hird, the president of Shield Advanced Solutions, many IBM i shops have no way to prevent users from accessing FTP. And once they’re using FTP, they have no way to tell what the users have done.

    “We were working with a lot of high availability customers, and we saw that none of them had any security on FTP,” Hird told IT Jungle at the recent POWERUp 2024 conference in Fort Worth, Texas. “They didn’t realize it ran.”

    FT4i logs all FTP activity on IBM i. (Image courtesy Shield Advanced Solutions)

    The lack of FTP security at IBM i shops could allow internal users to not only steal confidential information from the IBM i database, but to leave essentially no tracks, Hird said.

    “There’s nothing to stop any of those users from setting up something and stealing all your data,” he said. “If you have some salesperson who’s working for you, then all of a sudden he becomes a disgruntled employee and he’s going to move to another company, he can take the data with him, because you’ve got FTP running. You will never know.”

    The lack of security and logging around FTP concerned Hird so much that he decided to do something about it. The longtime C programmer realized that IBM provided the core components he needed to build a solution. The exit points in the operating system itself can control access to FTP and monitor FTP activity. Hird just needed to build a solution around those exit points to provide access control and logging for FTP, and that’s what he did.

    FT4i uses IBM exit points to restrict access to both the FTP server (incoming connections) and FTP client (command line outbound connections), to and from the IBM i. It works with plain vanilla FTP as well as FTPS and SFTP variants. It allows customers to shut down all FTP activity, to allow only certain users to work with FTP, to allow FTP only at certain times of the day, or work only with certain IP addresses.

    Additionally, FT4i logs all FTP activity. It keeps a database record of which users accessed FTP, when they accessed it, and the IP address on both ends of the connection.

    FT4i won’t be useful for IBM i shops that built their own exit point programs, or bought a third-party exit point solution. But for large fraction of IBM i shops that have done neither, FT4i can help close one of the biggest and most persistent security vulnerabilities on the IBM i platform, Hird said.

    “Not many people have the exit point solutions. They’re too expensive,” he said. “We’re more interested in getting the customer what they need at a reasonable price. For us it’s not about ‘Let’s get lots of value from this so we can sell the company.’ I think that’s the big difference, we don’t have investors to service. We’re self-funded, a small company. And we’re dedicated to the community, so we’ll sell it at what makes sense.”

    FT4i also integrates with other Shield products. If customers have Shield’s Nagios-based IBM i monitoring solution and its Grafana-based At A Glance (AAG) user interface, then they can be notified automatically when suspicious FTP activity is taking place.

    FT4i features Web-based and 5250 interfaces, giving customers a choice in how they interact with it. A subscription to FT4i costs $55 per month. For more information on the product, see www.shieldadvanced.com/Blog/announcement-ft4i-security-for-ibm-i/ or read Hird’s blog on FT4i at this link.

    RELATED STORIES

    Shield Adds HMC, Security PTFs to Nagios Monitoring Solution

    Shield Builds on Success with Nagios for IBM i

    Shield Launches Message Monitoring Offering for IBM i

    Shield Debuts Nagios Monitoring Solution for IBM i

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags: Tags: 5250, File Transfer Protocol, FT4i, FTP, FTPS, IBM i, SFTP, Shield Advanced Systems, SSH, TLS/SSL

    Sponsored by
    WorksRight Software

    Do you need area code information?
    Do you need ZIP Code information?
    Do you need ZIP+4 information?
    Do you need city name information?
    Do you need county information?
    Do you need a nearest dealer locator system?

    We can HELP! We have affordable AS/400 software and data to do all of the above. Whether you need a simple city name retrieval system or a sophisticated CASS postal coding system, we have it for you!

    The ZIP/CITY system is based on 5-digit ZIP Codes. You can retrieve city names, state names, county names, area codes, time zones, latitude, longitude, and more just by knowing the ZIP Code. We supply information on all the latest area code changes. A nearest dealer locator function is also included. ZIP/CITY includes software, data, monthly updates, and unlimited support. The cost is $495 per year.

    PER/ZIP4 is a sophisticated CASS certified postal coding system for assigning ZIP Codes, ZIP+4, carrier route, and delivery point codes. PER/ZIP4 also provides county names and FIPS codes. PER/ZIP4 can be used interactively, in batch, and with callable programs. PER/ZIP4 includes software, data, monthly updates, and unlimited support. The cost is $3,900 for the first year, and $1,950 for renewal.

    Just call us and we’ll arrange for 30 days FREE use of either ZIP/CITY or PER/ZIP4.

    WorksRight Software, Inc.
    Phone: 601-856-8337
    Fax: 601-856-9432
    Email: software@worksright.com
    Website: www.worksright.com

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Four Hundred Monitor, June 19 MDNA Launches Unit Testing Tool for IBM i

    Leave a Reply Cancel reply

TFH Volume: 34 Issue: 30

This Issue Sponsored By

  • Maxava
  • Connectria
  • Briteskies
  • OCEAN User Group
  • Raz-Lee Security

Table of Contents

  • IBM Banking on Merlin 2.0 to Goose Modern Development on IBM i
  • MDNA Launches Unit Testing Tool for IBM i
  • Shield Delivers Monitoring Solution for FTP on IBM i
  • Four Hundred Monitor, June 19
  • IBM i PTF Guide, Volume 26, Number 22

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • To Comfort The Afflicted And Afflict The Comfortable
  • How FalconStor Is Reinventing Itself, And Why IBM Noticed
  • Guru: When Procedure Driven RPG Really Works
  • Vendors Fill In The Gaps With IBM’s New MFA Solution
  • IBM i PTF Guide, Volume 27, Number 27
  • With Power11, Power Systems “Go To Eleven”
  • With Subscription Price, IBM i P20 And P30 Tiers Get Bigger Bundles
  • Izzi Buys CNX, Eyes Valence Port To System Z
  • IBM i Shops “Attacking” Security Concerns, Study Shows
  • IBM i PTF Guide, Volume 27, Number 26

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle