Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: FTP security hole in Windows NT 3.51
From: Jarle Aase <jgaa @ mail . jgaa . com>
Date: Wed, 19 Feb 1997 12:17:14 +0100
To: firewalls @ greatcircle . com
In-reply-to: <199702190925 . RAA10632 @ mnl . sequel . net>

At 17:29 19.02.97 +0800, MotivationAsia Philippines wrote:
>
>This may not be a firewall issue, but for the benefit of those using MS FTP
>Server either locally in their LANs or otherwise........
>With Internet Explorer 3.01 on Windows95, I typed ftp://ftp.mycompany.com.
>But instead of the FTP home directory initially showing, what showed was
>the root directory of drive E:. Somehow, I got the root directory of the
>drive as the FTP home directory.

There is a difference in how FTP clients and WEB browsers work. A FTP
client will normally log in and not issue a CD command unless you have
defined a "default directory" in the setup for the FTP site. If the client
don't give a CD command, the FTP server will determine what directory you
will log on to.

WEB browsers will always issue a CD command. If you don't specify a path in
the URL, they will issue a CD /, and use the FTP servers root path.

When it comes to security, it is your's responsibility to set the correct
file and directory permissions and, and to choose a sensible FTP root
directory. If you set the permission correct, most FTP systems will be
pretty safe. If you don't, ' it's like leaving the house with the doors and
windows wide open.

Jarle

-- 
Jarle Aase

Author of freeware.
 * HTMgen32 - the first usable multipage HTML generator/editor
 * WAR FTP DAEMON - the premier FTP server for Windows 95 and NT
 * WAR FTP CLIENT - the Win95/NT FTP client
 * wSendmail - sendmail and CGI-BIN utility for Win95/NT
 * War Install System - for easy, fast and reliable software installation

For support/suggestions: alt.comp.jgaa (newsgroup)
For information: info @
 mail .
 jgaa .
 com(email, auto-responder)
For info about known bugs and problems: buginfo @
 mail .
 jgaa .
 com 
                                        (email, autoresponder)
Private Email: jgaa @
 mail .
 jgaa .
 com

WWW: Primary site in USA http://www.jgaa.com/
WWW: Primary site in Norway: http://home.sol.no/jgaa/
   (-- among the most visited homepages in Norway --)
FTP: USA: ftp://ftp.jgaa.com/

<no need to argue - just kill'em all!>



References:
Indexed By Date Previous: ...no subject...
From: "LATINO Stephane" <Stephane . LATINO @ mail1 . sfr . fr>
Next: actions logging
From: mato @ intas . sk
Indexed By Thread Previous: FTP security hole in Windows NT 3.51
From: "MotivationAsia Philippines" <motivate @ mnl . sequel . net>
Next: ...no subject...
From: "LATINO Stephane" <Stephane . LATINO @ mail1 . sfr . fr>

Google
 
Search Internet Search www.greatcircle.com