FTP Attacks New Hampshire

FTP was built to be an extremely flexible protocol, and therein lie many of its security problems.

Local Companies

msrcco
(603) 642-6899
112 Crawley Falls Road
Brentwood, NH
New England Technology Supply
603-369-3570
31 Black Hall Rd
Epsom, NH
Localnet Corp
(603) 447-6446
Conway, NH
USA Datanet Corp
(603) 443-9992
Lebanon, NH
USA Datanet Corp
(603) 627-3100
Manchester, NH
MSRCCO
(603) 642-6899
112 Crawley Falls Road
Brentwood, NH
Fowler Computer
603-343-8331
71 Main St
Milton Mills, NH
Fowler Computer
603 343-8331
71 Main St
Milton Mills, NH
Ideaworks
(603) 427-2020
Portsmouth, NH
Flywire
(603) 430-3700
75 Congress St
Portsmouth, NH

provided by: 
Originally published at Internet.com


By Kurt Seifried (seifried@securityportal.com) for SecurityPortal -----------------------------------

FTP used to be the king of the Internet. If you wanted to download something you went to your favorite ftp server or used Archie to find the file. Even today, the number of ftp servers is staggering, and many ftp sites contain several hundred gigabytes of online archives (take a look at your local sunsite). FTP was built to be an extremely flexible protocol, and therein lie many of its problems. The FTP protocol not only allows you to transfer files from an ftp server to your machine but from one ftp server to another ftp server directly.

PASV Versus ACTIVE



The FTP protocol actually uses two channels for communications: a control channel and a data channel. The control channel uses tcp port 21. Clients connect to it from a local port (on Windows for example this is between 1024 and _1_5000 or so) and then send and receive information. When you request a file it is sent over the data channel which can behave in one of two ways.

With active ftp, the client specifies to the server how the transfer will be done. The client chooses a local port and tells the server to send data to it. The server initiates a connection from port 20 to the client and sends the data. The problems with this are numerous; the primary one being the firewalls must allow incoming connections from port 20 to a large selection of ports on internal machines. This allows attackers to easily scan internal machines by initiating connections from port 20...

Read article at Internet.com site

Featured Local Company

MSRCCO

(603) 642-6899
112 Crawley Falls Road
Brentwood, NH

Related Articles
- Zen and the Art of Breaking Security - Part II New Hampshire
There are cases in which "gentle" techniques like timing or power analyses are not enough to fulfill the attacker's goal. Or the goal itself is not to break the protection scheme but to break through it, to the end target the mechanism is protecting, in a modern reenactment of Alexander the Great's "solution" to the Gordian knot. Enter failure-inducing attacks, in which the technique is to induce a failure in the very protection mechanism itself.
- Why Firewalls? New Hampshire
Related Articles
- Zen and the Art of Breaking Security - Part II New Hampshire
There are cases in which "gentle" techniques like timing or power analyses are not enough to fulfill the attacker's goal. Or the goal itself is not to break the protection scheme but to break through it, to the end target the mechanism is protecting, in a modern reenactment of Alexander the Great's "solution" to the Gordian knot. Enter failure-inducing attacks, in which the technique is to induce a failure in the very protection mechanism itself.
- Why Firewalls? New Hampshire

Topics: 
Architecture & Design Languages & Tools Project Management Web Services
Database Microsoft & .NET Security Wireless
Java Open Source Techniques XML