Name

FTPT-688 — PASV family command response contains bad address

Severity

A (alert)

Message text

%s response illegal: %s

Description

The proxy received a response to PASV command, but the address is not the one of the control connection. Kernun FTP proxy checks these IP addreses and if they are not equal, the response (printed at the end of the message) is rejected. Under normal conditions, IP address is correct. The only "normal" situation when PASV response has different IP address is so called third party transfer - transfer between two remote servers. This kind of transfer is not allowed across Kernun FTP proxy. All other cases should mean an intrusion attempt.

Application exits.

See also

logging(7)

Authors

This man page is a part of Kernun Firewall.
Copyright © 2000–2023 Trusted Network Solutions, a. s.
All rights reserved.