Re: [fw-wiz] Variations of firewall ruleset bypass via FTP

From: Carson Gaspar (carsonat_private)
Date: Fri Oct 11 2002 - 11:31:32 PDT

  • Next message: Darren Reed: "Re: [fw-wiz] Variations of firewall ruleset bypass via FTP"

    --On Friday, October 11, 2002 10:40 AM +0200 Mikael Olsson 
    <mikael.olssonat_private> wrote:
    
    > Yes, if an attacker can create file names with CRLFs in them, we're
    > most likely screwed no matter what we're running.
    
    Unless the FTP software authors finally decide to support the RFC that 
    telnet-escapes CR.
    
    -- 
    Carson
    
    _______________________________________________
    firewall-wizards mailing list
    firewall-wizardsat_private
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards
    



    This archive was generated by hypermail 2b30 : Fri Oct 11 2002 - 12:28:26 PDT