SurgeFTP Weak Password Encryption Vulnerability
BID:3157
Info
SurgeFTP Weak Password Encryption Vulnerability
| Bugtraq ID: | 3157 |
| Class: | Design Error |
| CVE: |
CVE-2001-1356 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 04 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered by ByteRage <[email protected]>. |
| Vulnerable: |
NetWin SurgeFTP 2.0 f NetWin SurgeFTP 2.0 e NetWin SurgeFTP 2.0 d NetWin SurgeFTP 2.0 c NetWin SurgeFTP 2.0 b NetWin SurgeFTP 2.0 a |
| Not Vulnerable: | |
Discussion
SurgeFTP Weak Password Encryption Vulnerability
SurgeFTP is an ftp server for Windows and Unix platforms offered by NetWin.
SurgeFTP uses weak password hashing that allows for fast brute force cracking of the administrator password. The problem is that a single fixed salting method is used. This narrows the possible hash values and causes some hashes to correspond to multiple passwords.
SurgeFTP is an ftp server for Windows and Unix platforms offered by NetWin.
SurgeFTP uses weak password hashing that allows for fast brute force cracking of the administrator password. The problem is that a single fixed salting method is used. This narrows the possible hash values and causes some hashes to correspond to multiple passwords.
Exploit / POC
SurgeFTP Weak Password Encryption Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SurgeFTP Weak Password Encryption Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.