• Plesk Uservoice will be deprecated by October. Moving forward, all product feature requests and improvement suggestions will be managed through our new platform Plesk Productboard.
    To continue sharing your ideas and feedback, please visit features.plesk.com

possible security risk: ftplogin for webuser without valid password

R

rizi

Guest
hi,

can anybody confirm this? ->

i created a webuser under a normal domain:
www.testdomain.com/~webusername

i set the password "letmein" for that webuser.

now the user is able to login via FTP:
Code:
 ftp://webusername:[email protected]/

thats okay ... but I can set ANY string for password:
Code:
 ftp://webusername:[email protected]/
will work too....

changing password on the webuser-page in plesk does not take effect.

software: suse 9, plesk 7.5.2

thanks
love
rico
 
Webuser FTP login works correctly on my RH9/Plesk 7.5.2, passwords are treated properly.
 
Back
Top