[5777] in bugtraq
Re: CERT Advisory CA-97.27 - FTP_bounce
daemon@ATHENA.MIT.EDU (Aleph One)
Thu Dec 11 17:51:24 1997
Date: Thu, 11 Dec 1997 16:31:19 -0600
Reply-To: Aleph One <aleph1@DFW.NET>
From: Aleph One <aleph1@DFW.NET>
To: BUGTRAQ@NETSPACE.ORG
In-Reply-To: <19971211203211.36094@lk9qw.mail.eon.ml.org>
Note that this has been discussed a long time ago. I approved it becuse
it is still an issue. For a nice recount of both active and passive attack
read Secure Networks paper "Some problems with the File Transfer Protocol,
a failure of common implementations, and suggestions for repair" at
http://www.secnet.com/papers/ftp-paper.html
Aleph One / aleph1@dfw.net
http://underground.org/
KeyID 1024/948FD6B5
Fingerprint EE C9 E8 AA CB AF 09 61 8C 39 EA 47 A8 6A B8 01