OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Fw: Security hole in Win2K's FTP server
From: Noam Rathaus (dolittleBEYONDSECURITY.COM)
Date: Wed Jul 12 2000 - 15:15:41 CDT


Hi,

I don't know if you noticed this post, can anyone confirm this?

Thanks
Noam Rathaus.
----- Original Message -----
From: "Bob Kline" <bklineRKSYSTEMS.COM>
To: <BUGTRAQSECURITYFOCUS.COM>
Sent: Tuesday, July 11, 2000 23:59
Subject: Security hole in Win2K's FTP server

> Microsoft has introduced a security hole in the FTP server on Windows
> 2000 Professional. The properties panel for the service has controls
> for specifying "accept" or "deny" lists, and the online help explains
> how to use these controls to explicitly prohibit specific hosts from
> connecting to the service, or restrict access to an enumerated set of
> hosts. What the online help does not explain is that this security
> functionality has been turned off for the Professional version of
> Windows 2000. The intentional disabling of this feature (which was
> supported in NT Workstation 4.0, the predecessor of Windows 2000) is
> confirmed by an internal KnowledgeBase article within Microsoft.
>
> Most vendors improve functionality with later releases of their
> software, but I suppose there's an exception to every rule.
>
> --
> Bob Kline
>