OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: Extending the FTP "ALG" vulnerability to any FTP client
From: Dug Song (dugsongMONKEY.ORG)
Date: Sat Mar 11 2000 - 15:05:45 CST


On Fri, 10 Mar 2000, Mikael Olsson wrote:

> I'm theorizing. But that's what I did with the FTP PASV
> attack aswell, and right enough, less than a day later reports
> came dropping in, and a few days after that Dug Song had written
> a generic proof-of-concept hack. Care to type up another one?

since you asked so nicely. :-)

        http://www.monkey.org/~dugsong/ftpd-ozone.c.txt

reverse firewall penetration is really nothing new, though...

-d.

---
http://www.monkey.org/~dugsong/