Forum Moderators: open

Message Too Old, No Replies

Mozilla releases low-impact security patch

FTP PASV port-scanning

         

coopster

8:16 pm on Mar 21, 2007 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



[...] reported that a malicious web page hosted on a specially-coded FTP server could use this feature to perform a rudimentary port-scan of machines inside the firewall of the victim. By itself this causes no harm, but information about an internal network may be useful to an attacker should there be other vulnerabilities present on the network.

[mozilla.org...]

bill

4:11 am on Mar 22, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



Good to see that's a fix included in Firefox 2.0.0.3 and Firefox 1.5.0.11.

coopster

2:19 pm on Mar 22, 2007 (gmt 0)

WebmasterWorld Administrator 10+ Year Member



Yes, but users are encouraged to upgrade to the 2.x branch:


Note: Firefox 1.5.0.x will be maintained with security and stability updates until April 24, 2007. All users are encouraged to upgrade to Firefox 2.

[mozilla.org...]

bill

5:59 am on Mar 23, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member Top Contributors Of The Month



I still had a few machines on the 1.5 branch. Thanks for the heads-up coopster.