EFTP Clear Text Password Storage Vulnerability
BID:3332
Info
EFTP Clear Text Password Storage Vulnerability
| Bugtraq ID: | 3332 |
| Class: | Design Error |
| CVE: |
CVE-2001-1111 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 12 2001 12:00AM |
| Updated: | Jul 11 2009 07:56AM |
| Credit: | This vulnerability was posted to BugTraq by ByteRage <[email protected]>. |
| Vulnerable: |
Khamil Landross and Zack Jones EFTP 2.0.7 .337 |
| Not Vulnerable: | |
Discussion
EFTP Clear Text Password Storage Vulnerability
Encrypted FTP (EFTP) is both an FTP client and server application for Windows platforms.
EFTP stores all usernames and passwords in the file \Program Files\eftp2\eftp2users.dat in clear text. If a malicious user were to gain access to this file, they would have a list of all usernames and their associated passwords.
Encrypted FTP (EFTP) is both an FTP client and server application for Windows platforms.
EFTP stores all usernames and passwords in the file \Program Files\eftp2\eftp2users.dat in clear text. If a malicious user were to gain access to this file, they would have a list of all usernames and their associated passwords.
Exploit / POC
EFTP Clear Text Password Storage Vulnerability
There is no exploit code required to take advantage of this vulnerability.
There is no exploit code required to take advantage of this vulnerability.
Solution / Fix
EFTP Clear Text Password Storage Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
EFTP Clear Text Password Storage Vulnerability
References:
References:
- EFTP Main Page (Khamil Landross and Zack Jones)