Title: Hummingbird FTP Weak Password Encryption Weakness
Severity: LOW
Description:
Hummingbird FTP is an FTP client that is integrated with Windows Explorer.
Hummingbird FTP 2006 is prone to a weakness that could allow attackers to decrypt the password file.
The problem exists because the application does not sufficiently encrypt passwords stored in the user's FTP profile. The passwords may be decrypted by subtracting 125 from the ASCII value of each character in the password.
The Hummingbird Connectivity 10 FTP client is also reported to be prone to this weakness.
Affected Products:
- Hummingbird Connectivity 10.0.0
- Hummingbird FTP 2006 0.0.0
References:
- Hummingbird LTD.: Connectivity Home Page
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.