Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 16 Aug 2001 00:26:45 -0700
From:      "Crist J. Clark" <cristjc@earthlink.net>
To:        Ted Mittelstaedt <tedm@toybox.placo.com>
Cc:        Ruslan Ermilov <ru@FreeBSD.ORG>, Greg Lehey <grog@FreeBSD.ORG>, Ryan Thompson <ryan@sasknow.com>, William Nunn <yorkie123@hotmail.com>, freebsd-questions@FreeBSD.ORG
Subject:   Re: Remotely Exploitable telnetd bug
Message-ID:  <20010816002645.I330@blossom.cjclark.org>
In-Reply-To: <002501c1256a$e846ce00$1401a8c0@tedm.placo.com>; from tedm@toybox.placo.com on Wed, Aug 15, 2001 at 02:16:03AM -0700
References:  <20010815103807.D47417@sunbay.com> <002501c1256a$e846ce00$1401a8c0@tedm.placo.com>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, Aug 15, 2001 at 02:16:03AM -0700, Ted Mittelstaedt wrote:
> >-----Original Message-----
> >From: Ruslan Ermilov [mailto:ru@FreeBSD.ORG]
> >Sent: Wednesday, August 15, 2001 12:38 AM
> >To: Greg Lehey
> >Cc: Ted Mittelstaedt; Ryan Thompson; William Nunn;
> >freebsd-questions@FreeBSD.ORG
> >Subject: Re: Remotely Exploitable telnetd bug

[snip]

> >There are security extensions exist for FTP, see RFC2228 for details.
> >lukemftpd (currently in contrib/lukemftpd) is going to support these,
> >AFAIK.
> >
> 
> It's going to be many years before even a quarter of the FTP clients in use
> out there support these.

We can all hope and pray that FTP dies the slow and agonizing death it
deserves before we bother to hack security into this fundamentally
screwed up protocol.

Unfortunately, I think FTP will last as long as TCP/IP does.
-- 
Crist J. Clark                           cjclark@alum.mit.edu

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010816002645.I330>