[VulnWatch] Plaintext Password in Settings.ini of CesarFTP
From: Andreas Constantinides (megahz_at_megahz.org)
Date: 05/20/03
- Previous message: Florian Weimer: "[VulnWatch] Algorithmic Complexity Attacks and the Linux Networking Code"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
To: <vulnwatch@vulnwatch.org>, <bugtraq@securityfocus.com>, <news@securiteam.com> Date: Tue, 20 May 2003 10:15:59 +0300
Cesar FTP v0.99g (latest version)
an FTP Server by http://www.aclogic.com/
it saves the ftp password in file:
c:\Program Files\CesarFTP\settings.ini
in plaintext:
....
Password= "lalala"
Login= "megahz"
Name= "megahz"
....
Discovered by MegaHz
www.megahz.org
megahz@megahz.org
www.cyhackportal.com
- Previous message: Florian Weimer: "[VulnWatch] Algorithmic Complexity Attacks and the Linux Networking Code"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|