2002 Tech Tip: Problems With The FTP PORT Command or Why You Don't Want Just Any Port in a Storm
• White Paper
Describes the PORT command in FTP protocol, gives examples, and discusses solutions.
Publisher
Software Engineering Institute
Topic or Tag
Abstract
In the past few years, there have been ongoing discussions about problems related to the PORT command in the FTP protocol. These problems are based on the misuse of the PORT command in the FTP protocol.
The example attacks in this tech tip demonstrate the core component of the vulnerability: the contents of the FTP PORT command are not trustworthy as they are under the control of a potential attacker.