• Introducing WebPros Cloud - a fully managed infrastructure platform purpose-built to simplify the deployment of WebPros products !  WebPros Cloud enables you to easily deliver WebPros solutions — without the complexity of managing the infrastructure.
    Join the pilot program today!
  • Support for BIND DNS has been removed from Plesk for Windows due to security and maintenance risks.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS.

How to have freelance developers work on your server securely?

E

eggman2001

Guest
When I transfer files to my server, I always use SFTP so I'm minimizing the chances of someone else gaining ftp access to my server.

However, occasionally I have freelance developers work on my server (usually using a subdomain exclusively for development - i.e. dev.domain.com). When I send the developer the ftp login credentials, I do it via e-mail. I don't send them SFTP login info because they they could gain shell access and I don't want that.

Because I'm sending them the ftp login through e-mail, it's not secure. However, what would be the risks if this should fall into the wrong hands? Could someone upload a script that will attack my entire server? Or does plesk partition the directories in some way where they'd only be able to attack the folder that the malicious script gets placed in?

If what I'm doing is not secure, does anyone have any suggestions?
 
Back
Top