Re: CERT Advisory CA-97.27 - FTP_bounce

From: Barry Irwin (balinat_private)
Date: Fri Dec 12 1997 - 01:00:25 PST

  • Next message: Alfred Huger: "Re: CERT Advisory CA-97.27 - FTP_bounce"

    Aleph One
    >   Note that this has been discussed a long time ago. I approved it becuse
    > it is still an issue. For a nice recount of both active and passive attack
    > read Secure Networks paper "Some problems with the File Transfer Protocol,
    > a failure of common implementations, and suggestions for repair" at
    > http://www.secnet.com/papers/ftp-paper.html
    
    For those of you wanting to test this problem have a look at
    http://www.rootshell.com/hacking/ftpBounceAttack
    
    Barry
    
    
    --
    
    --
    "Ground Control to Major Tom; your circuits dead, there is something wrong.."
    ------------------------------------------------------------------------------
    Barry Irwin  aka Big Bastard From Hell
    bviat_private                       http://rucus.ru.ac.za/~bvi
    bbfhat_private                http://coredump.bofh.org.za
    -------------------------------------------------------------------------------
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 13:35:34 PDT