Bugtraq mailing list archives

Problems with FTGate


From: wizdumb () UNIX ZA NET (Andrew Lewis)
Date: Mon, 26 Jun 2000 20:23:08 +0200


The Problem:
------------
FTGate's POP3 server responds to invalid USER requests with a -ERR code
and doesn't disconnect you. This means that it is possible to bruteforce
usernames and passwords with ease.

Credit:
-------
Andrew Lewis aka. Wizdumb, One of the many losers from the MDMA crew
<www.mdma.za.net>


Current thread: