DSM-G600, DNS-3xx and NSA-220 Hack Forum

Unfortunately no one can be told what fun_plug is - you have to see it for yourself.

You are not logged in.

Announcement

#1 2009-10-03 23:36:13

ClipOn
Member
Registered: 2008-05-24
Posts: 8

DNS-323 FTP FW1.07: only Anonymous connections run ???

Hi,
I try to use the FTP Server on my DNS-323, and if I don't authorize Anonymous, I cannot get coonected with any other user. Either on port 21 or another.
With IE, I get a logon windows and no credentials run, and here is what I get in FileZilla:

Statut :    Connexion établie, attente du message d'accueil...
Réponse :    220---------- Welcome to Pure-FTPd [TLS] ----------
Réponse :    220-You are user number 1 of 10 allowed.
Réponse :    220-Local time is now 22:21. Server port: 21023.
Réponse :    220 You will be disconnected after 2 minutes of inactivity.
Commande :    USER cf
Réponse :    331 Any password will work
Commande :    PASS *****
Réponse :    530 Please tell me who you are

The message I don't understand is the response 331 to USER cf ??? And then the password seems to be the right one (length seems OK...) but is not accepted.
Where could be the problem ?
Many thanks
ClipOn


DNS-323  1.07  1To+1,5To     Samsung SpinPoint F1       No Raid   No Backup
DNS-323  1.07  1To+1,5To     Samsung SpinPoint F1       No Raid   Backup DNS to DNS via LAN each month with Robocopy

Offline

 

#2 2010-07-29 08:23:29

c22
New member
Registered: 2010-07-29
Posts: 2

Re: DNS-323 FTP FW1.07: only Anonymous connections run ???

My DNS-343 runs firmware 1.03, latest as of July 25, 2010, running the pure-ftpd that 343 1.03
firmware came with. Note the 1.03 on DNS-343 corresponds to something like 1.05 or 1.07
in DNS-323 land, I think. Mine gives a password error unless in the DNS-343 in
WebGUI, Advanced, Users the password set is short. My 12 char password always failed at
FTP login, my 8 char password always worked. The WebGUI shows only 9 dots represending characters
on password. Maybe the limit is 8 or 9 characters.

I am still trying to get PASV to work to allow remote access. I can't use Active(PORT) because
the client-side's NAT-firewall won't forward, and I have no control of it. I can only control my
DD-WRT router on the DNS-343 side. Pure-ftpd gives RANDOM ports all over for PASV.  I've seen 1605 up
through 45000. DMZ is too insecure. When I changed my port forwarding rule from a 10 port range,
to 1000 to 65000, then PASV from outside works fine. But too unsecure, and interferes with
other home PCs and their services. I seek a way to constrain pure-ftpd to a 10 port range for
pasv, that survives power cycles, and reboots. I have fun-plug up, SSH, but lack knowledge.

Pure-ftpd gives pasv replies like:
227 Entering Passive Mode (192,168,1,20,110,246)

That's always an illegal local IP 192.168.1.20 (DNS-343 on LAN), and port is calculated
110 * 256 + 246 here, 28406 tcp. For me, I can tolerate the 192,168,1,20 because I have
dynamic IP, dyndns.org, and am using Filezilla Client, open source. Filezilla Client
sees the 192,168,1,20 and says "unroutable address, using server address instead"
which sounds very helpful. It means it will use the server IP it connected
with for the command channel, nice. Of course I always timeout waiting for the first
directory. Now if I can make find a way to constrain pure-ftpd to a 10 port pasv range
for pasv, that survives power cycles, and reboots, I am happy.

Last edited by c22 (2010-07-29 08:55:13)

Offline

 

#3 2010-07-29 15:43:41

fordem
Member
Registered: 2007-01-26
Posts: 1938

Re: DNS-323 FTP FW1.07: only Anonymous connections run ???

I can't comment on the 343, but on a 323, you can forget about passive ftp with any firmware version prior to 1.08 - the implementation is incomplete, and from your post, it looks like it's the same on the 343.

Offline

 

Board footer

Powered by PunBB
© Copyright 2002–2010 PunBB