libunftp icon indicating copy to clipboard operation
libunftp copied to clipboard

Leaking user and group IDs in filesystem backend mode

Open mdirkse opened this issue 6 years ago • 0 comments

libunftp shows the actual owner uid and gid in the LIST output. I think this is a minor security issue. It should instead just return user ftp and group ftp.

We should make this configurable. vsftpd has a hide_ids option that is set to YES by default.

The question is, are we even bothered by this since we are using containers? Guess not?

mdirkse avatar Oct 18 '19 11:10 mdirkse