Re: CERT VU#539363

From: Darren Reed (avalon@coombs.anu.edu.au)
Date: 10/17/02


From: Darren Reed <avalon@coombs.anu.edu.au>
To: cswiger@mac.com (Chuck Swiger)
Date: Thu, 17 Oct 2002 10:12:06 +1000 (Australia/ACT)

In some mail from Chuck Swiger, sie said:
>
[...]
> OS X (or FreeBSD, for that matter) may not be vulnerable also because they
> don't try to monitor FTP transactions looking for the PASV, and thus don't
> create the bogus dynamic rule. Someone using static packet filtering
> rules (before a check-state) can block access to the low ports (below 1024)
> and mitigate against the spoofed dynamic rules.
[...]

You're confusing 539363 (state) with 328867 (FTP).

Darren

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: FreeBSDs problems as seen by the BSDForen.de community
    ... You cannot force a _volunteer_ to work on anything ... FreeBSD is mostly a project of volunteers, ... tree, ... They waste it on whatever they want, no matter ...
    (freebsd-current)
  • Re: Recommendations for a serial port card you can actually BUY?
    ... doesn't matter much. ... in that previous life when I bought my hardware (for FreeBSD ... ready to spend 500 dollars - these cost perhaps 10 a piece. ...
    (freebsd-stable)
  • Re: Abysmal mly Extreme RAID performance in 5.0-p7?
    ... What were the exact dd options you used for this? ... specify a block size, the default block size of 512 bytes is used, and ... with block sizes above that won't matter much. ... FreeBSD: The fastest and most stable server OS on the planet ...
    (freebsd-hackers)
  • Re: flashplugin
    ... since I can do it in a matter of seconds on a Microsoft product. ... On FreeBSD it requires manipulation precisely because *there is no plugin* for FreeBSD. ... It's a Linux plugin being adapted to FreeBSD using linux emulation, which adds a layer of complexity that Windows doesn't have to deal with. ...
    (freebsd-questions)
  • Re: Disk Errors
    ... Wojciech Puchar wrote: ... I read that FreeBSD doesn't use the BIOS at least for CHS. ... Hardware didnt seem to matter. ...
    (freebsd-questions)