Full Disclosure mailing list archives

Re: ws_ftp.log


From: "morning_wood" <se_cur_ity () hotmail com>
Date: Sun, 15 Aug 2004 09:05:10 -0700

your serious??
this issue has been arround for about 10 years...
try googling "ws_ftp.ini" where you can simply drop the
ini in your ws_ftp folder, convert the hashes or import into your
favorite ftp client that supports ws_ftp.ini style format.


m.wood

----- Original Message ----- 
From: "Gaurang Pandya" <gaubrig () yahoo com>
To: <full-disclosure () lists netsys com>
Sent: Sunday, August 15, 2004 5:19 AM
Subject: [Full-disclosure] ws_ftp.log


Hi,

WS_FTP is a popular & feature rich ftp client. It
makes upload/download as easy as drag & drop. But
mostly peoples using this forget that it creates a log
file with name ws_ftp.log. This file holds sensitive
data such as file source/destination and file name,
date/time of upload etc., People when use this to
upload files to their website, never know that along
with other files even ws_ftp.log file also gets
uploaded to the webserver, making it globally
accessible.


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: