Comprehensive data protection for all workloads
Post Reply
hirratas
Enthusiast
Posts: 56
Liked: 3 times
Joined: Feb 10, 2012 7:56 am
Contact:

Security of uploaded files during Support Call ( aws )

Post by hirratas »

Hello
when I upload files to a veeam support case it is being uploaded to aws and is available with a url.
This url can be accessed by anyone if he has this url (or was able to construct it) from anywhere and I can not check if and by whom the file has been downloaded.

Is this correct?
If yes, is there another way to send a file to veeam support. I think it makes sense that the file can only be accessed by the case handler (or his veeam account).

Because the files can contain sensitive information.
Thanks
Mildur
Product Manager
Posts: 8735
Liked: 2294 times
Joined: May 13, 2017 4:51 pm
Full Name: Fabian K.
Location: Switzerland
Contact:

Re: Security of uploaded files during Support Call ( aws )

Post by Mildur »

Hi Hirratas

Yes, if someone has access to this random generic URL or can create the URL with the file name and correct signature, he can access the logs.

As an alternative, please use SFTP to Veeam's own FTP Server (on demand access). While the SFTP link is publicly available, you would need credentials to access the content of the FTP folder. https://www.veeam.com/kb1661

Please see also this document which explains the different methods:
https://www.veeam.com/processing_of_sen ... ort_ds.pdf

Thanks
Fabian
Product Management Analyst @ Veeam Software
hirratas
Enthusiast
Posts: 56
Liked: 3 times
Joined: Feb 10, 2012 7:56 am
Contact:

Re: Security of uploaded files during Support Call ( aws )

Post by hirratas »

Ok, thanks. I will use sftp next time.
Post Reply

Who is online

Users browsing this forum: No registered users and 146 guests