TLS packet with unexpected length - *not* server reset prob

Need help with FileZilla Client? Something does not work as expected? In this forum you may find an answer.

Moderator: Project members

Message
Author
User avatar
boco
Contributor
Posts: 26934
Joined: 2006-05-01 03:28
Location: Germany

Re: TLS packet with unexpected length - *not* server reset p

#16 Post by boco » 2011-03-28 03:52

Status: Server did not properly shut down TLS connection
Do you get that error often? It would mean the server software (or rather anything in between, like a firewall) is broken and contains a security vulnerability. FileZilla deliberately denies to work with such servers. Please read http://forum.filezilla-project.org/view ... f=2&t=7688.

As to the firewall issue, the ''firewall'' term is to be seen loosely. Sadly almost every application nowadays even remotely related to security assumes that you need *yet* another firewall or port blocker. So even if you shut down Win7 firewall (which seems to be a dog, according to latest user reports), there still could be further software interfering. Seems to be something related to the Win7 machine, as the XP machine works. Anything with ''Internet security'' or similar in the name installed?
No support requests over PM! You will NOT get any reply!!!
FTP connection problems? Please read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
FileZilla Pro support: https://customerforum.fileZilla-project.org

sam_ok
503 Bad sequence of commands
Posts: 20
Joined: 2011-03-25 10:14
First name: Sam
Last name: Chan

Re: TLS packet with unexpected length - *not* server reset p

#17 Post by sam_ok » 2011-03-29 01:56

The network of the WINXP workstation is not the same as that of WIN7. I will plug in a WINXP workstation in the WIN7 network and carry out the test again.

Notify all of you the result later.

sam_ok
503 Bad sequence of commands
Posts: 20
Joined: 2011-03-25 10:14
First name: Sam
Last name: Chan

Re: TLS packet with unexpected length - *not* server reset p

#18 Post by sam_ok » 2011-04-01 06:47

I have finished testing using a WINXP workstation. It failed also. That means it is not Windows 7 problem.

After reviewing the firewall log, the FileZilla client ftp traffic was blocked by the firewall. The reason is "a potential Bounce Attack Evasion Attempt" or we may call it "ftp bounce" issue.

Why FileZilla client ftp traffic will be regarded as "ftp bounce" attack ?

User avatar
boco
Contributor
Posts: 26934
Joined: 2006-05-01 03:28
Location: Germany

Re: TLS packet with unexpected length - *not* server reset p

#19 Post by boco » 2011-04-01 09:48

Answer: Firewalls are paranoid.

If a client sends e. g. PORT commands with a different IP address than its own, the server tries to connect to that address instead. If it does that many times, you have what one calls an FTP bounce attack: The victims IP is flooded with requests by the server, while the actual attack originated elsewhere.
No support requests over PM! You will NOT get any reply!!!
FTP connection problems? Please read Network Configuration.
FileZilla connection test: https://filezilla-project.org/conntest.php
FileZilla Pro support: https://customerforum.fileZilla-project.org

Post Reply