Re: [fw-wiz] Active to Passive FTP translator?

From: Mikael Olsson (mikael.olsson@clavister.com)
Date: 11/27/02


From: Mikael Olsson <mikael.olsson@clavister.com>
To: "'firewall-wizards@honor.icsalabs.com'" <firewall-wizards@honor.icsalabs.com>
Date: Wed Nov 27 08:08:19 2002

Whoops. Tobias Reckhard caught a slip-up here:

Mikael Olsson wrote:
> - The java applet connects out through the firewall, to a fake FTP
> server under the attacker's control, and sends
> "PASV 192,168,0,1,5,153" (connect to me on port 1433)
> and then
> "RETR whatever.bin" (i want to receive data)

This should be "PORT 192,168,0,1,5,153", not "PASV".

"PASV" is, of course, used in passive mode, like this:

Client: "PASV"
Server: "227 Entering Passive Mode (1,2,3,4,5,6)"

... which is safe for the client, but not for the server.

-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com


Relevant Pages

  • Odd ftpd Problem
    ... My ftpd server fails when requesting passive mode from an internet client, ... I have a separate multi-homed server for the network firewall. ... except for the ftp passive mode. ...
    (linux.redhat.misc)
  • Re: [SLE] opensuse and ftp server
    ... The problem seems to start after the connection to the server when it ... so I don't remember which is which; in passive mode ... And, in recent SuSE versions, this should be handled transparently by the ... Yes I meant SuSE 10.0 oss, ...
    (SuSE)
  • Re: Microsoft FTP through Firewall
    ... 227 Entering Passive Mode ... address that the client will use to try to contact the server. ... FTP server that will allow you to specify the ip address you want to ...
    (comp.security.firewalls)
  • Re: Microsoft FTP through Firewall
    ... 227 Entering Passive Mode ... address that the client will use to try to contact the server. ... FTP server that will allow you to specify the ip address you want to ...
    (comp.security.firewalls)
  • Re: Linksys BEFSR41 V.2 and ftp
    ... I have WS_FTP Pro and a LinkSys Router and ZAP and connect to my ISPs ... in the browser nor the FTP setup page. ... through a proxy server and had changed the port. ... >>Try if it works when you set the FTP Client to passive mode (check the ...
    (comp.security.firewalls)