Blackmoon FTP Server Plaintext User Password Weakness
BID:7646
Info
Blackmoon FTP Server Plaintext User Password Weakness
| Bugtraq ID: | 7646 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 21 2003 12:00AM |
| Updated: | May 21 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Daniel Nyström. |
| Vulnerable: |
BlackMoon FTP Server 2.6 |
| Not Vulnerable: | |
Discussion
Blackmoon FTP Server Plaintext User Password Weakness
Blackmoon FTP Server stores authentication credentials for the FTP service on the local system in plaintext. Local users with access to the file containing the password may gain unauthorized access to the server as a result.
Exposure of authentication credentials may also lead to compromise of other services/resources if the same credentials are commonly used.
It should be noted that although this weakness was reported to affect Blackmoon FTP server version 2.6, previous versions might also be affected.
Blackmoon FTP Server stores authentication credentials for the FTP service on the local system in plaintext. Local users with access to the file containing the password may gain unauthorized access to the server as a result.
Exposure of authentication credentials may also lead to compromise of other services/resources if the same credentials are commonly used.
It should be noted that although this weakness was reported to affect Blackmoon FTP server version 2.6, previous versions might also be affected.
References
Blackmoon FTP Server Plaintext User Password Weakness
References:
References:
- BlackMoon FTP Homepage (BlackMoon)
- [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords (Daniel Nyström
)