Go Back   FlashFXP Forums > > > >

General Discuss anything and everything related to FlashFXP

 
 
Thread Tools Display Modes
Prev Previous Post   Next Post Next
Old 10-24-2002, 08:53 PM   #1
bigstar
FlashFXP Developer
FlashFXP Administrator
ioFTPD Beta Tester
 
bigstar's Avatar
 
Join Date: Oct 2001
Posts: 8,012
Default FlashFXP v1.4 - FlashFXP Local Password Disclosure Vulnerability

This problem seems to be getting a lot of attention lately so I thought I should clarify exactly what this means.

v1.4 had a feature that allowed you to edit queue items, due to the way the quick connect was designed there was no simple way to edit the site ip/login/pass, so I made it simple for the user and displayed this information in plain text on the queue item edit dialog. Only sites connected to via the quick connect displayed the login/password.

In v2.0 the quick connect was redone and this problem was eliminated.

FlashFXP Local Password Disclosure Vulnerability
http://www.securiteam.com/windowsntf...C00P0U5PE.html

RUMORS
As a result of misinformation or speculation, some rumors have come about stating that this problem results in sharing all of your hard drives with no password. Which is incorrect.
bigstar is offline  
 

Tags
connect, edit, flashfxp, password, quick


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 03:33 PM.

Parts of this site powered by vBulletin Mods & Addons from DragonByte Technologies Ltd. (Details)