Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Bugtraq: Re: ftpd: the advisory version

Re: ftpd: the advisory version

From: David Maxwell <david_at_FUNDY.CA>
Date: Sat, 8 Jul 2000 00:46:22 -0300

On Thu, Jul 06, 2000 at 06:20:14PM -0000, D. J. Bernstein wrote:
> Why are you allowing PORT-style FTP through your firewall? See RFC 1579.
> Can I scan port 6000 on your hosts if I set my source port to 20?
>
> Netscape uses PASV. The OpenBSD ftp client uses PASV. The Linux ftp
> client uses PASV if you give it the -p option. Internet Explorer uses
> PASV. What makes you think that requiring PASV will noticeably increase
> the level of user annoyance at your firewall?

A noticable set of sites have ftp servers which don't support PASV.

I say 'noticable' because if you manage a site with a fair sized user
base and turn active ftp support off, it won't take long for someone
to ask why some address doesn't work anymore.

Active ftp can be supported while preventing host scanning by including
NAT, or state-aware rules in your firewall setup. (If your software
supports it.)

--
David Maxwell, david_at_vex.net|david_at_maxwell.net -->
Any sufficiently advanced Common Sense will seem like magic...
					      - me
Received on Jul 10 2000
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]