Re: [fw-wiz] OBSD reaction to CERT advisory

From: Darren Reed (darrenr@reed.wattle.id.au)
Date: 10/10/02


From: Darren Reed <darrenr@reed.wattle.id.au>
To: Daniel Hartmeier <daniel@benzedrine.cx>
Date: Thu Oct 10 14:56:01 2002

In some email I received from Daniel Hartmeier, sie wrote:
[...]
> Mikael, can you recommend a suitable OS and ftp daemon combination that
> allows testing (the ftp server has commands that quote queries in the
> needed way and the OS' stack does partial retransmissions)?

Tell me what fool would agree to this setup ?

This is like a "Watch me tunnel IP packets over DNS and show you how
your firewall does not stop me hack internal boxes" where someone gets
to pick the DNS server on the inside and outside. Pick a vendor's
distribution that you think will work.

That brings me to another point, that was sorely missed in all the
public material I've seen so far, except maybe by Sun (and in the
wrong way) and that is you need a very special ftp daemon (i.e. not
any of the vendor ones I have tried) before it will stand a chance
of defeating IPFilter.

Darren



Relevant Pages

  • Re: forcing FTP-uploaded files to be of certain types only
    ... modify the source of the ftp daemon yourself. ... I'm not aware of any ftp server ... than the usual byte-sniffing done by file-- just try to compress ... message sent to the uploader instead: "Transfer aborted: please compress ...
    (freebsd-net)
  • Re: forcing FTP-uploaded files to be of certain types only
    ... modify the source of the ftp daemon yourself. ... I'm not aware of any ftp server ... than the usual byte-sniffing done by file-- just try to compress ... message sent to the uploader instead: "Transfer aborted: please compress ...
    (freebsd-isp)
  • Re: Debian (Woody) [bf2.4] Default FTP Server
    ... I don't recall it ever saying that. ... > I've heard wu-ftpd isn't as secure as proftpd. ... ftpd-ssl - FTP server with SSL encryption support. ... lukemftpd - The enhanced ftp daemon from NetBSD. ...
    (Debian-User)