Re: Problems with various windows FTP servers

From: Alun Jones (alun@texis.com)
Date: 05/31/02


Date: Fri, 31 May 2002 15:50:06 -0500
To: "SnakeByte / Eric Sesterhenn" <snakebyte@gmx.de>
From: Alun Jones <alun@texis.com>

At 01:39 PM 5/27/2002, SnakeByte / Eric Sesterhenn wrote:
>Texas Imperial Software WFTPD
> CWD ...
> CWD ....
> directory traversal possible

 From email received from SnakeByte out of band, it's clear that he's
working on an extremely old version of WFTPD, downloaded from a web site
that we are unfortunately unable to update due to errors in the automated
update procedures at that web site.

The bug he refers to has been reported to Bugtraq before, has been fixed,
and has been reported fixed on Bugtraq before.

The bug, if there is one, is that anything that is freely distributed is
always available in old versions. Always, always, always go to the source
of whatever software you use to at least check that you are running current
software, even if you don't download from that source directly.

Running extremely old software, as SnakeByte has shown, leaves you open to
extremely old bugs.

Alun.
~~~~

--
Texas Imperial Software   | Try WFTPD, the Windows FTP Server. Find us at
1602 Harvest Moon Place   | http://www.wftpd.com or email alun@texis.com
Cedar Park TX 78613-1419  | VISA/MC accepted.  NT-based sites, be sure to
Fax/Voice +1(512)258-9858 | read details of WFTPD Pro for NT.



Relevant Pages

  • Re: what gives?? Hey Microsoft, HEL-LO....
    ... It's a virus, and as more people click on the attachment ... Take a programming course, and learn more about your system - eventually ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Perplexed - who should I believe?
    ... used by phishers to confuse their targets, through public redirectors (Yahoo ... Does that mean it's safe to trust the http://www.tinyurl.com links? ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Washington WA 98072-8661 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.security)
  • Re: Security Bug in IE
    ... >people print out the contents of FTP sites, ... [Please don't email posters, if a Usenet response is appropriate.] ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.security)
  • Re: Need argument for scanning at Exchange
    ... should one of your customers get infected ... Disclosure is only one problem - what about corruption of patient data? ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.security)
  • Re: ssl negotiation failed with Microsoft IIS
    ... They can fail when you write first ssl packet header, ... [Please don't email posters, if a Usenet response is appropriate.] ... Texas Imperial Software | Find us at http://www.wftpd.com or email ... Cedar Park TX 78613-1419 | WFTPD, WFTPD Pro are Windows FTP servers. ...
    (microsoft.public.platformsdk.security)