[fw-wiz] Phrack #60: "Java tears down the Firewall"

From: Mikael Olsson (mikael.olsson@clavister.com)
Date: 12/28/02


From: Mikael Olsson <mikael.olsson@clavister.com>
To: fw-wiz <firewall-wizards@honor.icsalabs.com>
Date: Sat Dec 28 19:40:17 2002

Just a quick heads up re: Java and FTP and firewalls.
Looks like someone finally unleashed this evil on the public:
(I've been having fun with this in pen tests for 2+ years now :P)

http://www.phrack.org/show.php?p=60&a=3

Item 5: "Java tears down the Firewall", about two thirds down the page.

If your firewall can be configured to restrict protected clients so that
they are only allowed to use passive mode FTP, now would be a good time
to do so.

Free clue for people using "ftp.exe": http://www.ncftp.com/ncftp/

-- 
Mikael Olsson, Clavister AB
Storgatan 12, Box 393, SE-891 28 ÖRNSKÖLDSVIK, Sweden
Phone: +46 (0)660 29 92 00   Mobile: +46 (0)70 26 222 05
Fax: +46 (0)660 122 50       WWW: http://www.clavister.com


Relevant Pages

  • Re: Using Java Web Start
    ... What version of Java do they run. ... > I used this for a fairly controlled group of users, inside the firewall. ... > you to download and install Java. ... > writing detailed instructions on how to install the JRE, ...
    (comp.lang.java.programmer)
  • Re: Firewall or spywear affecting game discussion?
    ... firewall you installed, what was the name of that firewall? ... Online games are usually developed using Flash, Java, or Virtual Machine. ... The most likely solution to a problem with an online game is to install, upgrade, ...
    (microsoft.public.windowsxp.games)
  • Re: Natted IP
    ... >>local IP and can guess other protocols that might be allowed through the ... >>against a target and required for firewall protocol tunneling exploits. ... >>run only with JS enabled with Java applets disabled. ... tunnel through a firewall using blind protocols such as an exposed UDP ...
    (alt.computer.security)
  • Re: Unpatched Windows Vunerabilities
    ... OE or Messenger behind a firewall blocking all incoming ports? ... Why should I NOT install updates that make my system more secure against ... Tomcat, Media Man, and the Java Virtual Machine from MS. Try removing ...
    (comp.security.misc)
  • Re: Unpatched Windows Vunerabilities
    ... > Well, in a perfect world, while running Windows XP and not using any ... > things we had though were reasonably safe. ... > router that implements NAT a firewall? ... > Tomcat, Media Man, and the Java Virtual Machine from MS. Try removing ...
    (comp.security.misc)