Brought to you by:
Suppliers of:
A new version of the popular FTP daemon has been released. This version fixes numerous security vulnerabilities and hopefully concludes a series of minor releases, each containing numerous security holes.
Credit:
The latest ProFTPd can be downloaded from: ftp://ftp.tos.net/pub/proftpd/
ProFTP's homepage can be found here: http://www.proftpd.org
Almost all ProFTPd versions since 1.2.0pre2, were vulnerable to various exploits ranging from denial-of-service attacks to root compromise.
We reported those past vulnerabilities in previous articles:
ProFTPd vulnerable to a remote root compromise
ProFTPd version 1.2.0pre4 is still vulnerable to attack
A new version of ProFTPd (1.2.0pre5) closes security holes
Patch released for the new ProFTPd 1.2.0pre6 vulnerability
This new version is supposed to close all previous security holes. Meanwhile, until ProFTPd is tested and proven secure again, you might want to try an alternative secure anonymous FTP daemon: AnonFTPd, an anonymous read-only FTP Server .
Please enable JavaScript to view the comments powered by Disqus.
blog comments powered by