FlashFXP User Password Encryption Weakness
BID:7499
Info
FlashFXP User Password Encryption Weakness
| Bugtraq ID: | 7499 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 05 2003 12:00AM |
| Updated: | May 05 2003 12:00AM |
| Credit: | This issue has reportedly been public knowledge for a few years. Dvdman reported the issue recently and provided an exploit. |
| Vulnerable: |
FlashFXP FlashFXP 1.4 |
| Not Vulnerable: |
FlashFXP FlashFXP 2.0 |
Discussion
FlashFXP User Password Encryption Weakness
FlashFXP uses a trivially reversible algorithm to encrypt FTP user credentials. Local attackers with access to the sites.data may exploit this weakness to gain unauthorized access to FTP user credentials for remote sites.
FlashFXP uses a trivially reversible algorithm to encrypt FTP user credentials. Local attackers with access to the sites.data may exploit this weakness to gain unauthorized access to FTP user credentials for remote sites.
Exploit / POC
FlashFXP User Password Encryption Weakness
The following exploit was provided by Dvdman:
The following exploit was provided by Dvdman:
Solution / Fix
FlashFXP User Password Encryption Weakness
Solution:
This issue has been addressed through the Application Password Protection feature in FlashFXP version 2.0. Users should contact the vendor for details on obtaining this version.
Solution:
This issue has been addressed through the Application Password Protection feature in FlashFXP version 2.0. Users should contact the vendor for details on obtaining this version.