TFTP Server

mmaki

Member
Dec 27, 2000
77
0
0
I'm trying to get a TFTP server running on Debian. I'm starting the server with

in.tftpd -l /tmp

seems to start OK. I see an in.tftpd process.

I can connect to the server but if I try to get or put a file I get "Error code 2: Access violation"

/tmp is world readable and I placed a world readable file there.

I have commented out all entries in hosts.allow and hosts.deny.

An namp scan of the server only shows ports 68 (dhcpclient) and 6000 (X11) open. No port 69 as the /etc/services list for tftp.

Is there a log for tftpd that can give me more info?

Anything else I could have missed?
 

spidey07

No Lifer
Aug 4, 2000
65,469
5
76
I'm not familiar with that tftp server but.

tftp runs over udp, I can't remember if nmap tries udp ports

seems like your access rights are OK, is there some kind of .conf file that tells the tftp process where the root is?
 

mmaki

Member
Dec 27, 2000
77
0
0
I see there is a bug in this forum. I clicked post before I logged on, then logged on and it posted a blank reply. Any way...

The command in.tftpd -l /tmp starts the tftp daemon in stand alone mode (-l) using the /tmp directory as the tftp root directory. nmap does scan udp ports. I know this because I scanned an XP box running a little Windows tftp server and it found it.

Thanks for the reply though.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Check your configuration files. Chances are there is something that limits who can do what. I don't have Debian set up right now, so I can't check.
 

Fallen Kell

Diamond Member
Oct 9, 1999
6,161
510
126
ooo... Bad boy... tftp is bad thing to use unless you actually need to use tftp. TFTP, or Trivial File Transfer Protocal, is basically an anonomous ftp server. No authentication is used for connections. The only reason this protocol exists is because it was mainly used for diskless clients who load their OS services from a boot server. The diskless clients have no way of knowing what they are or what to do other then issue an ARP paket request basically saying "I exist and am online." A boot server will then recognise that packet and issue a response and then the diskless client will connect to the boot server using tftp.

Basically if you want to do anonomyous ftp, just use a normal ftp deamon and open up the permissions to allow anonomyous connections (its in the config files normally). TFTP should not be used for this application. It is nothing but a huge security risk.
 

mmaki

Member
Dec 27, 2000
77
0
0
I agree and understand the vulnerabilities tftp. It is only for a temporary situation to upload an IOS to Cisco router. I'm a little bummed because I had to break down and use some little WIN32 tftp app to do it. Couldn't get the Linux one to connect. I was trying KNOPPIX from a bootable CD and also a Debian install but both gave the same results. I'm sure there is a config somewhere that kept me from connecting. Thanks for the reply though.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |