Hi everyone,
I frequently run security scans against my BBS and in the reports I have put my attention to a potential vulnerability using the FTP bounce attack (1).
Thanks for the head's up. The Synchronet FTP server has (since 2001) rejected FTP-Bounces to reserved/system TCP ports (< 1024), so I'm not sure how "vulnerable" it really was, but in any case, I've committed a change to
disallow FTP Bounces to *any* TCP port on a 3rd party IP address, by default. --
| Sysop: | Gate Keeper |
|---|---|
| Location: | Shelby, NC |
| Users: | 812 |
| Nodes: | 20 (0 / 20) |
| Uptime: | 160:16:40 |
| Calls: | 13,500 |
| Calls today: | 1 |
| Files: | 5,294 |
| D/L today: |
3 files (503K bytes) |
| Messages: | 611,125 |