[13899] in bugtraq
Re: FireWall-1 FTP Server Vulnerability
daemon@ATHENA.MIT.EDU (Nick FitzGerald)
Thu Feb 17 22:19:22 2000
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: 7BIT
Message-Id: <200002171040.XAA28745@fep4-orange.clear.net.nz>
Date: Thu, 17 Feb 2000 23:36:47 +1200
Reply-To: nick@virus-l.demon.co.uk
From: Nick FitzGerald <nick@VIRUS-L.DEMON.CO.UK>
X-To: BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To: <E12L2AG-000795-00@taurus.cus.cam.ac.uk>
<<much snipped>>
> Even with the best firewall in the world, I'm pretty convinced that
> you need an ftp server that implements the FTP protocol correctly
> before you have a hope of handling PASV correctly.
Which is a different way of making the point Greg Hoglund did in a
recent-ish ntbugtraq post (Subject: Crappy code is crappy code ...)
that a firewall has an icicle's chance in hell of adequately
mimicking a system it is supposed to protect if it does so purely on
the assumption that the code it is protecting works "correctly" by
the firewall developer's interpretation of "correct".
Regards,
Nick FitzGerald