MegaBrowser FTP User Enumeration Weakness
BID:7803
Info
MegaBrowser FTP User Enumeration Weakness
| Bugtraq ID: | 7803 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 04 2003 12:00AM |
| Updated: | Jun 04 2003 12:00AM |
| Credit: | Discovery of this issue is credited to JeiAr <[email protected]>. |
| Vulnerable: |
MegaBrowser MegaBrowser 0.3 |
| Not Vulnerable: | |
Discussion
MegaBrowser FTP User Enumeration Weakness
MegaBrowser is prone to a user enumeration weakness. When attempting to authenticate via the FTP service, MegaBrowser will respond differently based on whether or not an FTP user name exists. This could aid in brute force attacks that attempt to compromise FTP user accounts.
MegaBrowser is prone to a user enumeration weakness. When attempting to authenticate via the FTP service, MegaBrowser will respond differently based on whether or not an FTP user name exists. This could aid in brute force attacks that attempt to compromise FTP user accounts.
Exploit / POC
MegaBrowser FTP User Enumeration Weakness
There is no exploit required.
There is no exploit required.
Solution / Fix
MegaBrowser FTP User Enumeration Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
MegaBrowser FTP User Enumeration Weakness
References:
References:
- MegaBrowser Homepage (MegaBrowser)
- MegaBrowser HTTP and FTP Vulnerabilities (JeiAr
)