FTP: Request to Connect to Illegal Port

This protocol anomaly triggers when it detects an FTP PORT command/response to a PASV command ("227...") that specifies a reserved port number. This can indicate an attempt to make IDP or firewall open reserved ports.

Extended Description

PASV commands specifying a reserved port may be the result of misconfigured, or badly implemented, FTP clients. It could also indicate that an attacker is attempting an FTP Bounce Attack, or similar.

Short Name
FTP:EXPLOIT:ILLEGAL-PORT
Severity
Major
Recommended
False
Recommended Action
None
Category
FTP
Keywords
CVE-2006-2225
Release Date
04/22/2003
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown
CVSS Score

7.5

Found a potential security threat?