EFTP Password Hash Retrieval Vulnerability
BID:3331
Info
EFTP Password Hash Retrieval Vulnerability
| Bugtraq ID: | 3331 |
| Class: | Input Validation Error |
| CVE: |
CVE-2001-1109 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 12 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | Discovered and posted to Bugtraq by ByteRage <[email protected]> on Sep 12, 2001. |
| Vulnerable: |
Khamil Landross and Zack Jones EFTP 2.0.7 .337 |
| Not Vulnerable: | |
Discussion
EFTP Password Hash Retrieval Vulnerability
If a logged in EFTP user connects to an external share and submits a malformed 'list' command, the user could force the FTP server to make an external SMB connection.
The FTP server must provide login credentials of the user the server is running under in order to make a connection to the remote host. A password hash is sent across the external connection to the host. A third party network utility could be listening for internal and external traffic and capture the password hash. The captured hash could be resolved into the username and password.
If a logged in EFTP user connects to an external share and submits a malformed 'list' command, the user could force the FTP server to make an external SMB connection.
The FTP server must provide login credentials of the user the server is running under in order to make a connection to the remote host. A password hash is sent across the external connection to the host. A third party network utility could be listening for internal and external traffic and capture the password hash. The captured hash could be resolved into the username and password.
Exploit / POC
EFTP Password Hash Retrieval Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
EFTP Password Hash Retrieval Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EFTP Password Hash Retrieval Vulnerability
References:
References:
- EFTP Main Page (Khamil Landross and Zack Jones)