Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: ftpd: the advisory version

Re: ftpd: the advisory version

From: Steven M. Bellovin <smb_at_RESEARCH.ATT.COM>
Date: Wed, 5 Jul 2000 20:46:34 -0400

In message <200007021934.MAA01251_at_lart>, Tom Perrine writes:

...
>
>However, the port-1024 thing must be laid directly at the feet of the
>Berkeley folks. That ports<1024 must be "trusted" (for various values
>of "trust") was a hack they put in so that they could delegate
>responsibilty for authenticaion and other things to the client-side
>host in the notorious "r-command" protocols.
>
>"Of course we can trust this unencrypted, unverified data; it came
>from a host somewhere that was probably running UNIX, and from a
>low-numbered port, therefore it was running as root, and therefore
>should be trusted completely, no additional authentication required."

...
>
>To be slightly less inflammatory, they (Berkeley) were quite correct
>in their port 1024 hack, based on their assumptions:

No, they weren't, and they knew it. Dragging out my ancient 4.2bsd
manual:

        "The authentication procedure used here assumes the integrity
        of each client machine and the connecting medium. This is
        insecure, but is useful in an "open" environment.

        "A facility to allow all data exchanges to be encrypted
        should be present."

They used the word "insecure", not me...
Received on Jul 06 2000

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos