PaulDotCom mailing list archives

Ideas for Securing my FTP Server


From: shauncurry1 at gmail.com (Shaun Curry)
Date: Sun, 22 Mar 2009 13:03:15 -0500

Well... I was up til 3am trying to get OpenBSD to work with a GNOME desktop
environment (remember I come from a windows background).  I never got it to
work so I have moved on to Ubuntu.  This should allow me to use daemonshield
and some decent firewall software (maybe firestarter?!).

Also, I found a little something on Milw0rm about an exploit for serv-u ftp
server.

" A vulnerability is caused due to an input validation error when handling
FTP "MKD" requests. This can be exploited to escape the FTP root and create
arbitrary directory on the system via directory traversal attacks using the
"\.." character sequence."

http://www.milw0rm.com/exploits/8211

Thank you very much everyone for all your help!  This has been a lesson I
will never forget.

Shaun
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://mail.pauldotcom.com/pipermail/pauldotcom/attachments/20090322/8b9f20a5/attachment.htm 


Current thread: