From owner-freebsd-security@FreeBSD.ORG Tue Jan 25 17:23:00 2005 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 520E416A4CE for ; Tue, 25 Jan 2005 17:23:00 +0000 (GMT) Received: from wproxy.gmail.com (wproxy.gmail.com [64.233.184.207]) by mx1.FreeBSD.org (Postfix) with ESMTP id C5C6443D1D for ; Tue, 25 Jan 2005 17:22:57 +0000 (GMT) (envelope-from swhetzel@gmail.com) Received: by wproxy.gmail.com with SMTP id 58so426717wri for ; Tue, 25 Jan 2005 09:22:57 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:cc:in-reply-to:mime-version:content-type:content-transfer-encoding:references; b=RrkR3YBshn8EE/eKEFpqTgmXz5BFhAvpFpGRrVVgZiLIrmfBoEigCmAFyLfP+p22EAwT7LXp2aHb3wAiQevgUgw9IdswPlDfQx2WVMQ0nbEkdoCd1XuZb4UL0ljHkfv5VciY5k7bNJjaQRZ30b/BKX/HTmHgmo8Sc9RgvMvS90o= Received: by 10.54.49.9 with SMTP id w9mr100296wrw; Tue, 25 Jan 2005 09:22:57 -0800 (PST) Received: by 10.54.29.48 with HTTP; Tue, 25 Jan 2005 09:22:56 -0800 (PST) Message-ID: <790a9fff050125092264ab2008@mail.gmail.com> Date: Tue, 25 Jan 2005 11:22:56 -0600 From: Scot Hetzel To: Endin Suprana In-Reply-To: <20050125081634.28383.qmail@web80902.mail.scd.yahoo.com> Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit References: <00c201c502b3$39958930$3501a8c0@pro.sk> <20050125081634.28383.qmail@web80902.mail.scd.yahoo.com> cc: FreeBSD Security Subject: Re: ftp problem X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: Scot Hetzel List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 25 Jan 2005 17:23:00 -0000 On Tue, 25 Jan 2005 00:16:34 -0800 (PST), Endin Suprana wrote: > Thx for reply, > > You're right i have typo it..:-) > > I did what you suggest, uncommented entry "ALL : ALL : > allow" in /etc/hosts.allow and turn on IPFW verbose. > Also add rule for ipfw: > # ipfw add 10 allow all from any to any > > i've checked /var/log/security, but nothing's logged > there. > It could be a reverse DNS lookup problem. As the ftpd is trying to get the reverse name and it is timingout the connection due to it is waiting for a reply from the DNS servers. Check to make sure the host your trying to connect from is in your DNS servers (or add it to the /etc/hosts file on the ftpd server). Scot