The following got no response on -security two weeks ago.  Perhaps
-current will have more opinions.

---------- Forwarded message ----------

I have found quite a few commands that ftpd shouldn't necessarily be
responding to if the user hasn't logged in.  In total, the following
commands are taught to not talk to strangers: TYPE, STRU, MODE, ALLO,
ABOR, SITE IDLE, SYST, REST.  Many of these were obtained from OpenBSD.


See http://www.fxp.org/~jedgar/ftpcmd.y.diff for the diff.

-----
Chris D. Faulhaber - [EMAIL PROTECTED] - [EMAIL PROTECTED]
--------------------------------------------------------
FreeBSD: The Power To Serve   -   http://www.FreeBSD.org






To Unsubscribe: send mail to [EMAIL PROTECTED]
with "unsubscribe freebsd-current" in the body of the message

Reply via email to