FTP home directory bug

Risk Level: Low risk vulnerability  Low

Check or Attack Name: ftphome

Platforms: FTP
Description:

The FTP daemon revealed the true path to the FTP user's home directory by issuing a quote cwd command. This information gathering probe may give an attacker clues as to the basic structure of the victim's file system. Many modern FTP server packages have removed this flaw, but some (like wu-ftp) are still vulnerable.

Remedy:

This feature is built in to many FTP servers; refer to your server's documentation on how to disable the CWD command.

References:

Academ Consulting Services, WU-FTP Server Software Release Information, http://ftp.academ.com/academ/wu-ftpd/release.html


X-Force Logo
Know Your Risks