We are running a plain packet filter, only allowing certain services.
We allow outbound 21 (ftp) and 20 either way. (ftpdata) We have no
ftpd in our inetd.conf, so we don't care about inbound ftpdata.
With this setup a user can run the normal ftp client and get files
out on the internet. When Netscape sees a page reference and it is
an ftp reference, it always hangs trying to download.
When I turned off the firewall, and looked real careful, I see extra
services being referenced. For instance, try
http://www.1soft.com/download.html
When you select to download something, it tries to open a much higher
service number, which seems to change at will:
208.146.49.105:2045
Next time
208.146.49.105:2047
Next day
208.146.49.105:3048
My packet filter is blowing off these services, of course, so the FTP
fails.
Is there any pattern to this? Is there some convention I am missing?
Am I right in assuming some risk to allowing services 2000-3000 to
play through my firewall?
--
---------------------------------------------------------------------------
Neal Rhodes MNOP Ltd (770)-
972-5430
President Lilburn (atlanta) GA 30247 Fax:
978-4741
http://www.mnopltd.com/