Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 18 Dec 2004 13:43:55 +0100
From:      DanGer <danger@wilbury.sk>
To:        wsx <security@noc.kstu-kai.ru>, freebsd-security@freebsd.org
Subject:   Re: Active ftp connection
Message-ID:  <12410554059.20041218134355@wilbury.sk>
In-Reply-To: <200412181518.55782.security@noc.kstu-kai.ru>
References:  <200412181518.55782.security@noc.kstu-kai.ru>

next in thread | previous in thread | raw e-mail | index | archive | help
Hello wsx,

Saturday, December 18, 2004, 1:18:55 PM, si napisal:

> Hello dear friends...

> I have a trouble. My FTP server must have an active ftp connection.
> It means what in ipfw rules I must allow outgoing connections(like ipfw add
> allow tcp from me to any keep-state).
> But I don't want use this rule. I want to restrict my outgoing connections. Is
> FreeBSD have a feature for this situation?

  what about allowing these outgoing connection only for ftpd's port?

> P.S. 
>         Only for test we developed little root-kit, which can use only outgoing
> connections. example:
> 1. rootkit gets a command from remote machine
> 2. do this command.
> 3. connects to remote machine and returns result.
> So we havn't got connections to my server, only outgoing..

> Best regards..

-- 
CU soon

+----------==/\/\==----------+       (__)      FreeBSD
| DanGer <danger@wilbury.sk> |    \\\'',)      The
| DanGer@IRCnet ICQ261701668 |      \/  \ ^    Power
| http://danger.homeunix.org |      .\._/_)    To
+----------==\/\/==----------+                 Serve



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?12410554059.20041218134355>