WS_FTP Weak Stored Password Encryption Vulnerability
BID:547
Info
WS_FTP Weak Stored Password Encryption Vulnerability
| Bugtraq ID: | 547 |
| Class: | Design Error |
| CVE: |
CVE-1999-1078 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 29 1999 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | Vulnerability discovered and posted to NTBugtraq July 29, 1999 by Bernardo Quintero of Hispasec <[email protected]> |
| Vulnerable: |
Ipswitch WS_FTP Pro 6.0 Ipswitch WS_FTP LE 5.0 Ipswitch WS_FTP LE 4.5 |
| Not Vulnerable: | |
Discussion
WS_FTP Weak Stored Password Encryption Vulnerability
WS_FTP, both Pro and LE versions,. allows passwords to be saved as part of a saved site configuration. These passwords are encrypted and stored in .ini files. The encryption method is weak and can be broken.
WS_FTP, both Pro and LE versions,. allows passwords to be saved as part of a saved site configuration. These passwords are encrypted and stored in .ini files. The encryption method is weak and can be broken.
Exploit / POC
WS_FTP Weak Stored Password Encryption Vulnerability
This page contains Javascript that will decrypt an encrypted password taken out of the .ini file.
http://www.hispasec.com/wsftp.asp
This page contains Javascript that will decrypt an encrypted password taken out of the .ini file.
http://www.hispasec.com/wsftp.asp
Solution / Fix
WS_FTP Weak Stored Password Encryption Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
WS_FTP Weak Stored Password Encryption Vulnerability
References:
References: