Re: CERT Advisory CA-97.27 - FTP_bounce

Aleph One (aleph1@DFW.NET)
Thu, 11 Dec 1997 16:31:19 -0600

Note that this has been discussed a long time ago. I approved it becuse
it is still an issue. For a nice recount of both active and passive attack
read Secure Networks paper "Some problems with the File Transfer Protocol,
a failure of common implementations, and suggestions for repair" at
http://www.secnet.com/papers/ftp-paper.html

Aleph One / aleph1@dfw.net
http://underground.org/
KeyID 1024/948FD6B5
Fingerprint EE C9 E8 AA CB AF 09 61 8C 39 EA 47 A8 6A B8 01