FlashFXP 1.4 Local Password Disclosure Vulnerability

From: Blud Clot (bludclot@hellokitty.com)
Date: 10/22/02


From: "Blud Clot" <bludclot@hellokitty.com>
To: bugtraq@securityfocus.com
Date: Tue, 22 Oct 2002 16:24:48 -0500

Description: Local users may be able to view passwords for ftp sites.

Versions affected: This was discovered on FlashFXP 1.4 (build 800). It is likely, but not tested, that any version 1.x is vulnerable. FlashFXP 2.x is not vulnerable.

Vendor Contacted: E-mailed CEDsoft on 8/31/02. They responded within hours and informed me that they had already known about this vulnerability and that their publicly available beta version already had it fixed.

Details: When passwords are entered into FlashFXP they are generally echoed with asterisks, but there is an exception. When there are transfers in the queue the password is visible in cleartext by editing the queue properties.

Solution: Upgrade to the latest version.

Personal Note: I was very impressed with their response time and commitment to security.

-BludClot

-- 
____________________________________________________
Get your own Hello Kitty email @ www.sanriotown.com

Powered by Outblaze



Relevant Pages

  • [NT] FlashFXP Local Password Disclosure Vulnerability
    ... FlashFXP offers the easiest and fastest way to ... A vulnerability allows local users to discover the FTP ... passwords used in the product. ... In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages. ...
    (Securiteam)
  • Re: Field for Credit Card Number
    ... by the browser's form entry history/auto fill, like passwords are, but without the asterisks? ... Better World News TV Channel: ...
    (comp.infosystems.www.authoring.html)
  • Re: autocomplete in IE6
    ... help you recover other cached passwords *before* you clear all passwords. ... Then using AutoComplete for that userid delete that userid. ... the asterisks and assume that the password will be presented properly. ...
    (microsoft.public.windows.inetexplorer.ie6.browser)
  • Re: Redhat 9 - Newbie question about users and groups
    ... > configured a user with the users and groups app on the start up menu. ... It just shows all passwords with the same number of asterisks, ... (Hint: ...
    (alt.os.linux.redhat)
  • Re: #@!%&* Google
    ... that mistake. ... Since passwords are displayed as asterisks, ... Used the earthlink address ...
    (soc.senior.issues)

Quantcast