Facebook Google Plus Twitter LinkedIn YouTube RSS Menu Search Resource - BlogResource - WebinarResource - ReportResource - Eventicons_066 icons_067icons_068icons_069icons_070

ProFTPD < 1.2.11 Remote User Enumeration



The remote host may give an attacker information useful for future attacks.


The remote ProFTPd server is as old or older than 1.2.10. It is possible to determine which user names are valid on the remote host based on timing analysis attack of the login procedure. An attacker may use this flaw to set up a list of valid usernames for a more efficient brute-force attack against the remote host.


Upgrade to version 1.2.11 or higher.