SGI IRIX ftpd PASV Mode Data Channel...

- AV AC AU C I A
发布: 2002-08-14
修订: 2025-04-13

The FTP server included with SGI IRIX is vulnerable to hijacking of data connections when PASV mode is in use. When in PASV mode, the server listens on a port when a transfer of data is to occur. The client then connects and the data is transferred. SGI has reported that the ftpd selects predictable PASV mode port numbers. As a result, it is trivial for remote attackers to hijack data connections and retrieve data before the client can.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息