Security Flaw with Linux 2.4 Kernel and IPTables
Tempest Security Advisory:
Security Flaw with Linux 2.4 Kernel and IPTables [via Slashdot]
Security Advisory – #01/2001
Security flaw in Linux 2.4 IPTables using FTP PORT
Author: Cristiano Lincoln Mattos, CISSP, SSCP
Systems affected: Firewalls using Linux Kernel 2.4.x with IPTables
Release date: 16 April 2001
Platforms: Linux Kernel 2.4.x
Impact: If an attacker can establish an FTP connection passing through a Linux 2.4.x IPTables firewall with the state options allowing “related” connections (almost 100% do), he can insert entries into the firewall’s connection tables…