Vulnerabilities > CVE-2004-1602 - Information Exposure Through Discrepancy vulnerability in Proftpd

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
proftpd
CWE-203
nessus
exploit available

Summary

ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which allows remote attackers to identify valid usernames by timing the server response.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionProFTPD. CVE-2004-1602. Remote exploit for linux platform
idEDB-ID:581
last seen2016-01-31
modified2004-10-17
published2004-10-17
reporterLeon Juranic
sourcehttps://www.exploit-db.com/download/581/
titleProFTPD <= 1.2.10 - Remote Users Enumeration Exploit

Nessus

NASL familyFTP
NASL idPROFTPD_USER_ENUM.NASL
descriptionThe remote ProFTPd server is as old or older than 1.2.10 It is possible to determine which user names are valid on the remote host based on timing analysis attack of the login procedure. An attacker may use this flaw to set up a list of valid usernames for a more efficient brute-force attack against the remote host.
last seen2020-06-01
modified2020-06-02
plugin id15484
published2004-10-17
reporterThis script is Copyright (C) 2004-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/15484
titleProFTPD Login Timing Account Name Enumeration