Re: Scan for anonymous ftp...

From: larstr@no-spam.colargol.tihlde.org
Date: 01/31/02


From: larstr@no-spam.colargol.tihlde.org
Date: Thu, 31 Jan 2002 11:23:59 +0000 (UTC)

P.c <micael.ka@telia.com> wrote:
: If someone is scanning for anonymous Ftp:s is that ok? I read one RFC (don't
: remember the number..) that said if you have an anonymous Ftp its the same
: as go ahead and d/l or upload if that is permitted.

Most ftp sites have a policy. Read it carefully first.

: As portscanning usually is not something that firewalladmins and ISP:s are
: so fond off does anyone know if its "wrong" to scan a broad range of ip:s on
: port 21 if you are only looking for anonymous Ftp:s (which of course is
: impossible to see in the firewall) ??

: And if its "wrong" (according to the netiquette or the law in whatever
: country) is it "written" down (RFC??)

: Is it okay to do this in let say U.S.A or any other country?

no, it's not ok. scanning for ftp is considered equally to port scanning.
We've seen alot of automated ftp scripts that finds an anonymous ftp server
with write permissions, tags it with a "unerasable" direcory structure and
moves on to the next ip address.

After a while you start getting warez or similar stuff in this directory
structure. This is not legal and is usually reported by the firewall admin
when it is discovered.

This often also chews up all of the victims bandwidth.

Lars



Relevant Pages

  • Re: LAN issue with FTP
    ... We are unable to install the scanning software on this ... >>It is my understanding that the scanning software uses ftp to communicate ... this pc will not install this software. ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: [Whitehat] BIND scan from Wanadoo.fr
    ... > I am used to seeing those idiots scanning for FTP and I have them all ... > REJECTs and when I investigated I found 62.155/11 scanning for BIND .. ... I am not observing any bind scans from that subnet, but I am seeing a lot ... of IIS script exploit attemtps and PHP content disposition exploit ...
    (Incidents)
  • BIND scan from Wanadoo.fr
    ... I am used to seeing those idiots scanning for FTP and I have them all ... REJECTs and when I investigated I found 62.155/11 scanning for BIND .. ... For more information on this free incident handling, ...
    (Incidents)
  • Re: address already in use
    ... Our networ scanner software was running an ftp ... server for scanning to FTP I just had to change the port ...
    (microsoft.public.inetserver.iis.ftp)
  • Re: Problem about Window Xp SP2 firewall and the buildin FTP command
    ... Problem about Window Xp SP2 firewall and the buildin FTP ... I find a problem that if running multiple FTP command at the same ... Windows XP SP2 to limit Max Connections/sec ...
    (microsoft.public.windowsxp.general)