When a user logs into the server, SmartFTD-D checks for a special user file and if it exists configuration information (such as the user"s password, rights, etc.) will be read from the file.
During the login process the service doesn"t check for illegal characters, and therfore by using "..\" characters an intruder can switch to other directories where a Trojan user configuration file could have been stored via anonymous upload or via a user with valid access to the system.
VENDOR RESPONSE
Mindstorm is aware of this matter and will publish a correction in their next product build, however no date has been given for the release of the next build.
CREDITS
|
SmartFTP Exposes File System
0 comments
Hide comments