A product can be used as an intermediary or proxy between an
attacker and the ultimate target, so that the attacker can either bypass access
controls or hide activities.
FTP bounce attack. Protocol allows attacker to
modify the PORT command to cause the FTP server to connect to other machines
besides the attacker's. Similar to proxied trusted
channel.
Potential Mitigations
Phase
Description
Enforce the use of strong mutual authentication mechanism between the
two parties.
This entry is currently a child of CWE-610 under view 1000, however there
is also a relationship with CWE-668 because the resulting proxy effectively
exposes the victims control sphere to the attacker. This should possibly be
considered as an emergent resource.
Content History
Submissions
Submission Date
Submitter
Organization
Source
PLOVER
Externally Mined
Modifications
Modification Date
Modifier
Organization
Source
2008-07-01
Eric Dalci
Cigital
External
updated Potential Mitigations,
Time of Introduction
2008-09-08
CWE Content Team
MITRE
Internal
updated Relationships, Observed Example, Other Notes,
Taxonomy Mappings
2008-11-24
CWE Content Team
MITRE
Internal
updated Maintenance Notes, Relationships,
Taxonomy Mappings, Time of Introduction