Great Circle Associates Firewalls
(June 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: ftp problem
From: Alex Filacchione <alexf @ iss . net>
Date: Mon, 24 Jun 1996 11:53:43 -0400
To: Darwin Martinez <Darwin_Martinez @ INS . COM>
Cc: "firewalls @ GreatCircle . COM" <firewalls @ GreatCircle . COM>


----------
From: 	Dave Roberts[SMTP:djr @
 saa-cons .
 co .
 uk]
Sent: 	Friday, June 21, 1996 6:53 AM
To: 	Darwin Martinez
Cc: 	firewalls @
 GreatCircle .
 COM
Subject: 	Re: ftp problem

On Thu, 20 Jun 1996, Darwin Martinez wrote:

> When I ftp to a site, FW-1 allows the ftp connect (21) but then blocks the
> return data (ftp-data 20?). My rulebase allows both ftp & ftp-data from the
> internal nets outward. I'm doing NAT. After i connect, i see the actions

You would need to allow incoming connection from the outside port 20, to
the inside port >1023 (probably excluding the X11 ports). 


If you do this, then will you not be opening up potential source porting problems?  Incoming TCP connections from port 20 on an attacking machine would make it through, no?  Isn't the purpose behind PASV ftp specifically to stop this potential problem?  Something to think about.

Alex F

=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
Alexf @
 iss .
 net
Marketing Specialist
Come visit the growing Vulnerability Database
http://www.iss.net
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=


Follow-Ups:
Indexed By Date Previous: Re: Firewall1 log
From: Bill Stout <bill . stout @ hidata . com>
Next: Re: Gauntlet - How good is it?
From: Bill Stout <bill . stout @ hidata . com>
Indexed By Thread Previous: Re: ftp problem
From: chris . liljenstolpe @ ssds . com (Christopher Liljenstolpe)
Next: Re: ftp problem
From: eckes <ecki @ lina . inka . de>

Google
 
Search Internet Search www.greatcircle.com