Checkpoint FW-1 and "ftp missing newline char" attack

From: Liam Dolan (lgdolan_at_gmail.com)
Date: 09/29/04


Date: 29 Sep 2004 10:06:59 -0700

Howdy.

I'm trying to log in to a customer's ftp server from an AIX 5.3 box
behind FW-1. This is eventually going to be a cron job, but right now
I'm trying it manually for testing purposes.

I *have* to use passive mode.

Logging in defaults to active. No problem cding, lsing, getting, etc.
Then I issue the passive command, after which any attempt to use the
data port completely hangs the session.

Checking SmartView Tracker says that the firewall rejected the data
request due to an 'ftp missing newline char' attack, and subsequent
packets get dropped because they're out of state.

The admin at the customer site swears up and down that he's got
passive mode enabled and the high ports open to me on his end. I've
tried logging in to both his AS/400 and his MS box with the same
results.

Anybody have any ideas?

Thanks.

I should probably add that ncftp, which apparently defaults to passive
mode for data transfer, hangs in the same way as the normal client.



Relevant Pages

  • Re: Passive FTP on ISA Server 2000
    ... >I cannot connect to ftp server that uses passive mode, ... > ISA Server: extended error message: ... > are configured as web proxy client, and some are using Firewall Client ...
    (microsoft.public.isa)
  • Passive FTP on ISA Server 2000
    ... I cannot connect to ftp server that uses passive mode, ... ISA Server: extended error message: ... Proxy client settings that discussed on the article on isaserver.org is only ...
    (microsoft.public.isa.clients)
  • Passive FTP on ISA Server 2000
    ... I cannot connect to ftp server that uses passive mode, ... ISA Server: extended error message: ... Proxy client settings that discussed on the article on isaserver.org is only ...
    (microsoft.public.isa)
  • Passive FTP on ISA Server 2000
    ... I cannot connect to ftp server that uses passive mode, ... ISA Server: extended error message: ... Proxy client settings that discussed on the article on isaserver.org is only ...
    (microsoft.public.isa.configuration)
  • Re: Support for passive FTP
    ... > I'd like to support passive mode FTP connections to my VMS FTP server, ... > the security risk by opening only those ports which the FTP server might ... Which VMS and TCPIP versions? ... At least VMS 7.3 with TCPIP services 5.3 can do passive mode. ...
    (comp.os.vms)