A server we have at a POP that uses the Astaro Office FW 4.0 has been hacked. The hackers used the open Port 21 to gain access to the ftp Server to exchange MP3 files...
The odd thing is: the operator tells me that while they got in through Port 21, the outgoing traffic was via Ports upward of 4000. These Ports are supposedly blocked on the Astaro (for outgoing as well).
He told me, that once a client and a server negotiate a new port to use for traffic, the firewall can't do anything about it.
I'm not an expert, but I thought that was one of the reasons for having a firewall in the first place? Is he trying to weasel out of a bad configuration, or is there substance to the story?
Thank you much for your help!
[:S]
This thread was automatically locked due to age.