Blackmoon FTP Server Username Information Disclosure Vulnerability
BID:7647
Info
Blackmoon FTP Server Username Information Disclosure Vulnerability
| Bugtraq ID: | 7647 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 21 2003 12:00AM |
| Updated: | May 21 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to Daniel Nyström. |
| Vulnerable: |
BlackMoon FTP Server 2.6 |
| Not Vulnerable: | |
Discussion
Blackmoon FTP Server Username Information Disclosure Vulnerability
It has been reported that BlackmoonFTP Server is prone to an information disclosure weakness.
The problem exists in the way the FTP server handles the authentication procedure. An attacker may exploit this weakness to enumerate valid usernames.
It should be noted that although this weakness was reported to affect Blackmoon FTP server version 2.6, previous versions might also be affected.
It has been reported that BlackmoonFTP Server is prone to an information disclosure weakness.
The problem exists in the way the FTP server handles the authentication procedure. An attacker may exploit this weakness to enumerate valid usernames.
It should be noted that although this weakness was reported to affect Blackmoon FTP server version 2.6, previous versions might also be affected.
References
Blackmoon FTP Server Username Information Disclosure Vulnerability
References:
References:
- BlackMoon FTP Homepage (BlackMoon)
- [[ TH 026 Inc. ]] SA #4 - Blackmoon FTP Server cleartext passwords (Daniel Nyström
)