Web Hack List

Collected research

Bypass port blocking in Firefox, Opera and Konqueror.

BindShell.Net: Manipulating FTP Clients Using The PASV Command

FTP clients follow the IP address a server returns in its PASV reply, so a malicious FTP server can redirect a browser's data connection to any host and port. This defeats Firefox port banning, extending JavaScript port scanning to every TCP port, and the same-origin handling permits banner grabbing off-origin; services returning no banner are fingerprinted by how long they hold an idle connection open.

Record

Document
BindShell.Net: Manipulating FTP Clients Using The PASV Command
Researcher
mark
Published by
bindshell.net
Topic
Browser

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of mark, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .