Hello,
thanks for that little program, it serves me well, and I'm considering packaging it for the Debian Linux distribution.
However, there's an issue: It seems ftp-proxy has no safeguard against requesting files from outside the given base directory, in other words, "get ../../../etc/passwd" will happily deliver that file - something that shouldn't happen from a security point of view.
Hello,
thanks for that little program, it serves me well, and I'm considering packaging it for the Debian Linux distribution.
However, there's an issue: It seems ftp-proxy has no safeguard against requesting files from outside the given base directory, in other words, "get ../../../etc/passwd" will happily deliver that file - something that shouldn't happen from a security point of view.