Great Circle Associates Firewalls
(August 1994)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: intercepting ftp data connections
From: z056716 @ uprc . com (LaCoursiere J. D. (Jeff))
Date: Thu, 4 Aug 1994 18:05:19 +0800
To: firewalls @ greatcircle . com

I brought up this question recently at Brent's Dallas class... he thought
the list might find it interesting:

Has anyone ever attempted to intercept and forge the data channel to an
ftp client?  The situation I envision would be a machine on the path between
client and server sniffing packets; the machine would detect an ftp session
in progress and wait for the client to issue the data channel's port number.
At this point, the forger would inject packets to open the connection to
the waiting client, hopefully timed correctly to reach the client before 
the real packets from the server arrive.  The server's open would fail
(I am assuming ftp only listens for one connection), causing an error on
the command channel I guess.  I suppose this may tip off the client to drop
the connection that succeeded, but I'm not sure.  If not, couldn't the forger
feed the client whatever?  Say a trojaned version of what they were really 
looking for?

cheers,


        ______/   Jeff LaCoursiere                   FastLane Communications
       /          Network security/services          mail info @
 flc .
 uprc .
 com
      ___/        lacoursj @
 uprc .
 com
     /
  __/  ASTLANE  Communications!  Connecting America to the Internet...
        

Indexed By Date Previous: Re: Screening & routers
From: "Daniel O'Callaghan" <danny @ cwis . unimelb . edu . au>
Next: SKEY on a BSDI machine
From: "Charles B. Kaplan" <cbk @ magna . telco . com>
Indexed By Thread Previous: [no subject]
From: "'Jack Grey'" <jackgrey @ iglou . com>
Next: SKEY on a BSDI machine
From: "Charles B. Kaplan" <cbk @ magna . telco . com>

Google
 
Search Internet Search www.greatcircle.com