FTP PASV port denial of service attack |
---|
Risk Level: | Medium | Check or Attack Name: FTP PASV Denial of Service |
---|---|---|
Platforms: | FTP | |
Description: | A vulnerability exists in many FTP server packages that allows an attacker to endlessly request PASV (passive) connections to the server. Eventually, this attack depletes all the ports on the system, denying legitimate traffic to the machine. |
|
Remedy: | Update your FTP server. Wu-FTP: The latest version of wu-ftp is available from ftp://ftp.academ.com/pub/wu-ftpd/ or at http://ftp.academ.com/academ/wu-ftpd/release.html. Windows NT: Apply the latest Windows NT 4.0 Service Pack, or the ftp-fix patch:
Download and apply the ftp-fix patch from ftp://ftp.microsoft.com/bussys/iis/iis-public/fixes/usa/security/ftp-fix/. |
|
References: | Microsoft Knowledge Base Article Q189262, FTP Passive Mode May Terminate Session, http://support.microsoft.com/support/kb/articles/q189/2/62.asp |
Know Your Risks |