Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2004-1602 PoC — ProFTPd登录时间差异用户帐户泄露漏洞

Source
Associated Vulnerability
Title:ProFTPd登录时间差异用户帐户泄露漏洞 (CVE-2004-1602)
Description:ProFTPd是一款流行的FTP服务程序。 ProFTPd在处理'USER'命令时对非法用户名处理存在时间差异,远程攻击者可以利用这个漏洞验证合法用户帐户名。 LSS Security Team报告通过对ProFTPd登录过程进行代码执行路径时间分析,可判断合法用户帐户名。远程用户估量传输'USER'命令和应答时间的差异,可判断帐户是否合法。
Description
ProFTPD versions 1.2.x (including 1.2.8 and 1.2.10) are vulnerable to timing attacks that allow remote attackers to distinguish valid usernames from invalid ones. The server responds in varying amounts of time when a given username exists, enabling username enumeration through response time analysis.
File Snapshot

id: CVE-2004-1602 info: name: ProFTPD 1.2.x - Username Enumeration via Timing Attack author: pu ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.