I'm setting up an FTP server to share some pictures temporarily for about 20 people. I want to allow people to upload or download pictures for a period of about a month. I tried this before and used anonymous access, and eventually got hacked and was storing some pirated movies or something. I have since learned my lesson with that, and I reformatted and reinstalled the OS to take care of that issue.
I'm using Windows 2000 and have IIS configured to allow Reads and Writes. I created a restricted Windows account with password to allow access. I do have an Administrator account created with a non-obvious password.
Even with the username/password what security risks am I opening myself up for? And are there any better (simple) alternatives? I've done some web searches and I've read conflicting views.
Thanks in advance.
-- Gary