|
|
|
|
| |
| When installing FtpXQ with default settings, it is possible through anonymous and/or through the username and password of 'test' for a remote attacker to gain read/write access to whole drive c: of the computer upon the product was installed. |
| |
Credit:
The information has been provided by Brice Carlson.
|
| |
Vendor response:
... Yes, those IDs are configured by default to have access for the C:\ drive for the purpose of an administrator testing the server. We assume that every responsible administrator will run the server first in a test environment, and not in a production setting, or on an IP that is exposed to the internet. Administrators should obviously change the access for both of these accounts and/or change the User IDs before putting it into a production environment. Because of your email however, we will change the default access for the anonymous user to be read only, as well as post a message at the end of the install noting the default access for the test users...
Workaround:
Make sure you delete the account 'test', modify its password, or restrict its access. Disable anonymous access.
|
|
|
|
|