TCP Port 21
Common Use
FTP Service is typically is server where you upload/download files from.
Inbound Scan
If you are running a FTP server and have forwarded port 21 on your firewall
then you need to setup a port forward within Link Logger such that future
inbound traffic on this port will be logged as normal and not as an alert.
There are scans which look for FTP Servers, either anonymous or with weak passwording
or have vulnerabilities. Also some virus or trojans use FTP to download
components.
Outbound Scan
By default Link Logger raises an alerts on outbound traffic to this port in
order to alert administrators to use of unauthorized FTP servers. Servers can
be trusted such that future traffic to the authorized FTP server will not
appear as an alert.
Additional Information
ProFTPD fails to properly
handle newline characters when transferring files in ASCII mode
WS_FTP Server vulnerable
to buffer overflow when supplied overly long "APPE" command
WS_FTP Server vulnerable
to buffer overflow when supplied overly long "STAT" command
Page last updated on
February 09, 2004
|