[Full-disclosure] Apple Airport Wireless Products: Promiscuous FTP PORT Allowed in FTP Proxy Provides Security Bypass
Sabahattin Gucukoglu
mail at sabahattin-gucukoglu.com
Tue Mar 9 05:26:01 GMT 2010
On 6 Mar 2010, at 02:12, drstrangep0rk at hushmail.com wrote:
Do you have firmware information on which products it affects.
Tested with firmware 7.5 on the latest-generation units. Should work just fine with 7.4.2, on the previous generation. These are the latest versions. I don't know about previous releases for Airport Express, Airport Extreme, or Time Capsule, and what revisions they will be at. They will probably be affected as long as they offer FTP access, which I think was true for Airport Extreme from the beginning.
Cheers,
Sabahattin
Full-Disclosure is hosted and sponsored by Secunia.