Full Disclosure mailing list archives

Re: Apple Airport Wireless Products: Promiscuous FTP PORT Allowed in FTP Proxy Provides Security Bypass


From: Sabahattin Gucukoglu <mail () sabahattin-gucukoglu com>
Date: Tue, 9 Mar 2010 05:26:01 +0000

On 6 Mar 2010, at 02:12, drstrangep0rk () hushmail com wrote:
Do you have firmware information on which products it affects.

Tested with firmware 7.5 on the latest-generation units.  Should work just fine with 7.4.2, on the previous generation. 
 These are the latest versions.  I don't know about previous releases for Airport Express, Airport Extreme, or Time 
Capsule, and what revisions they will be at.  They will probably be affected as long as they offer FTP access, which I 
think was true for Airport Extreme from the beginning.

Cheers,
Sabahattin

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: