Re: [Proftpd-user] rstatus response
TJ Saunders <[email protected]>
| Newsgroups | gmane.network.proftpd.user |
|---|---|
| Message-ID | <1487971800.4135220.892111016.64AEE21C@webmail.messagingengine.com> |
> What you response also made me realize is that the line that contains > “ProFTPD” is also hardcoded as well as probably the rest of the response > to ‘rstatus’. My concern now is that this whole response is a “giveaway” > to a potential intruder because if a string (Status of “ServerName”) with > specific structure appears in a particular place in the response to known > command, one can deduce the product because only this product prints this > in response to STAT. Unless RFC dictates that STAT is responded with this > particular verbiage. > > What do you think? ProFTPD will respond to a STAT command only if the client has authenticated, so it's a "giveaway" of information to users that you have already allowed. (If you don't trust your users, then you have other issues.) This, combined with the ability to change that information via ServerName, to me suggests that the "leak", if construed as such, is not that large. TJ ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, SlashDot.org! http://sdm.link/slashdot _______________________________________________ ProFTPD Users List <[email protected]> Unsubscribe problems? http://www.proftpd.org/list-unsub.html