Rumpus FTP Server Plaintext Password Vulnerability
BID:2718
Info
Rumpus FTP Server Plaintext Password Vulnerability
| Bugtraq ID: | 2718 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Unknown |
| Published: | May 15 2001 12:00AM |
| Updated: | May 15 2001 12:00AM |
| Credit: | Jass Seljamaa <[email protected]> posted this vulnerability to BugTraq on May 15th, 2001. |
| Vulnerable: |
Maxum Rumpus FTP Server 2.0.3 dev Maxum Rumpus FTP Server 1.3.4 Maxum Rumpus FTP Server 1.3.2 |
| Not Vulnerable: | |
Discussion
Rumpus FTP Server Plaintext Password Vulnerability
Rumpus FTP Server is an implementation for MacOS which allows file-sharing across TCP/IP connections.
Passwords are stored in plaintext format in the prefs folder.
If access to the prefs folder is not restricted then a remote user may view the plaintext password file and access any user account on the server.
Rumpus FTP Server is an implementation for MacOS which allows file-sharing across TCP/IP connections.
Passwords are stored in plaintext format in the prefs folder.
If access to the prefs folder is not restricted then a remote user may view the plaintext password file and access any user account on the server.
Exploit / POC
Rumpus FTP Server Plaintext Password Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Rumpus FTP Server Plaintext Password Vulnerability
Solution:
The vendor has confirmed the existence of the issue and will be addressing it in future releases of the software.
Solution:
The vendor has confirmed the existence of the issue and will be addressing it in future releases of the software.
References
Rumpus FTP Server Plaintext Password Vulnerability
References:
References:
- Rumpus FTP Server Product Page (Maxum)