Re: Defend against FTP bounce attack
By: Karloch to All on Mon Feb 15 2021 01:16 am
Hi everyone,
I frequently run security scans against my BBS and in the reports I have put my attention to a potential vulnerability using the FTP bounce attack (1).
Thanks for the head's up. The Synchronet FTP server has (since 2001) rejected FTP-Bounces to reserved/system TCP ports (< 1024), so I'm not sure how "vulnerable" it really was, but in any case, I've committed a change to disallow FTP Bounces to *any* TCP port on a 3rd party IP address, by default.
--
digital man
This Is Spinal Tap quote #15:
Review on "Shark Sandwich", merely a two word review: "Shit Sandwich".
Norco, CA WX: 59.8øF, 57.0% humidity, 0 mph W wind, 0.00 inches rain/24hrs
---
þ Synchronet þ Vertrauen þ Home of Synchronet þ [vert/cvs/bbs].synchro.net