FTP

Safari FTP PASV manipulation vulnerability

Release date

September 16th, 2015

 

Vulnerability description

The localhosed attack (stealing IE localhost cookies)

This extended advisory describes a vulnerability in Microsoft Internet Explorer 11/10/9/8/7 (on Windows Vista and above). The vulnerability allows stealing cookies for local machine domains/IP addresses. Additionally, the local IP address used by IE to communicate to the Internet is exposed (even if behind a NAT or a SOCKS proxy). On Windows XP, IE 8-6 are vulnerable to the IP exposure vulnerability only.

Filezilla FTP server is vulnerable to FTP PORT bounce attack and PASV connection theft

Filezilla FTP server is vulnerable to FTP PORT bounce attack and PASV connection theft

Date: May 6th, 2015

Subscribe to RSS - FTP