PDA

View Full Version : passive, limiting port range?


michal
03-07-2004, 05:50 AM
hey, im on dsl connection shared via wingate software. the problem is that due to security reasons only *some* of the ports on the server can be opened, which makes ftp connections almost impossible. lets take one site as an example. it uses port 2398 as the "entrance" port, so i unlocked it and i can easily connect to it. however, when i try to transfer any files or browse the contents, flashfxp attempts to connect on virtually every port from the range (~8000 - 65535 <-- thats what ive witnessed so far). if i allow all 'connections to internet' on wingate, i get no errors, but as ive written earlier - i cannot do it long-term.

the question is: is there a way to force flashfxp to transfer data on a specific range of ports in passsive mode?

Raccoon
03-07-2004, 06:08 AM
No, there is not, otherwise it would be called Active mode (PORT).

You can certainly limit the range of ports that FlashFXP issues with the PORT command, but this poses an even greater security risk than simply letting your machine establish outbound connections on any/all ports.

I'd like to add that there shouldn't be any risk to your machine or network's security by allowing outbound connections to any/all ports. You may successfully stop a virus or backdoor that is already on your system from "phoning home", but even then, most would probably use port 80. The only time network administrators do this is to prevent students/workers from playing online games or using peer-to-peer software.

You might consider just leaving the wingate open, unless there's some risk that I don't know about.

- Raccoon

MxxCon
03-07-2004, 06:12 AM
indeed, like Raccoon mentioned, in PASV mode server tells YOU which ports to use..it doesn't matter what client you are using.

you can only limit ports if you use PORT mode.