ProFTPD Authentication Delay Username Enumeration Vulnerability
BID:11430
Info
ProFTPD Authentication Delay Username Enumeration Vulnerability
| Bugtraq ID: | 11430 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 15 2004 12:00AM |
| Updated: | Oct 15 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to LSS Security. |
| Vulnerable: |
ProFTPD Project ProFTPD 1.2.9 rc3 ProFTPD Project ProFTPD 1.2.9 rc2 ProFTPD Project ProFTPD 1.2.9 rc1 ProFTPD Project ProFTPD 1.2.9 ProFTPD Project ProFTPD 1.2.8 rc2 ProFTPD Project ProFTPD 1.2.8 rc1 ProFTPD Project ProFTPD 1.2.8 ProFTPD Project ProFTPD 1.2.7 rc3 ProFTPD Project ProFTPD 1.2.7 rc2 ProFTPD Project ProFTPD 1.2.7 rc1 ProFTPD Project ProFTPD 1.2.7 ProFTPD Project ProFTPD 1.2.6 ProFTPD Project ProFTPD 1.2.5 rc1 ProFTPD Project ProFTPD 1.2.5 ProFTPD Project ProFTPD 1.2.4 ProFTPD Project ProFTPD 1.2.3 ProFTPD Project ProFTPD 1.2.2 rc3 ProFTPD Project ProFTPD 1.2.2 rc1 ProFTPD Project ProFTPD 1.2.2 ProFTPD Project ProFTPD 1.2.1 ProFTPD Project ProFTPD 1.2 pre9 ProFTPD Project ProFTPD 1.2 pre8 ProFTPD Project ProFTPD 1.2 pre7 ProFTPD Project ProFTPD 1.2 pre6 ProFTPD Project ProFTPD 1.2 pre5 ProFTPD Project ProFTPD 1.2 pre4 ProFTPD Project ProFTPD 1.2 pre3 ProFTPD Project ProFTPD 1.2 pre2 ProFTPD Project ProFTPD 1.2 pre11 ProFTPD Project ProFTPD 1.2 pre10 ProFTPD Project ProFTPD 1.2 pre1 ProFTPD Project ProFTPD 1.2 .0rc3 ProFTPD Project ProFTPD 1.2 .0rc2 ProFTPD Project ProFTPD 1.2 .0rc1 ProFTPD Project ProFTPD 1.2 |
| Not Vulnerable: | |
Discussion
ProFTPD Authentication Delay Username Enumeration Vulnerability
A timing attack is described in ProFTPD that could assist a remote user in enumerating usernames.
A remote attacker may exploit this vulnerability to determine what usernames are valid, privileged, or do not exist on the remote system.
A timing attack is described in ProFTPD that could assist a remote user in enumerating usernames.
A remote attacker may exploit this vulnerability to determine what usernames are valid, privileged, or do not exist on the remote system.
Exploit / POC
ProFTPD Authentication Delay Username Enumeration Vulnerability
The following exploit is available:
The following exploit is available:
Solution / Fix
ProFTPD Authentication Delay Username Enumeration Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ProFTPD Authentication Delay Username Enumeration Vulnerability
References:
References:
- LSS Security Advisory #LSS-2004-10-02 (LSS Security)
- ProFTPD Home Page (ProFTPD)
- ProFTPD 1.2.x remote users enumeration bug (LSS Security
)