FTP home directory bug |
---|
Risk Level: | Low | Check or Attack Name: ftphome |
---|---|---|
Platforms: | FTP | |
Description: | The FTP daemon revealed the true path to the FTP user's home directory by issuing a quote cwd command. This information gathering probe may give an attacker clues as to the basic structure of the victim's file system. Many modern FTP server packages have removed this flaw, but some (like wu-ftp) are still vulnerable. |
|
Remedy: | This feature is built in to many FTP servers; refer to your server's documentation on how to disable the CWD command. |
|
References: | Academ Consulting Services, WU-FTP Server Software Release Information, http://ftp.academ.com/academ/wu-ftpd/release.html |
Know Your Risks |