id: CVE-2004-1602 info: name: ProFTPD 1.2.x - Username Enumeration via Timing Attack author: pussycat0x severity: medium description: | ProFTPD versions 1.2.x (including 1.2.8 and 1.2.10) are vulnerable to timing attacks that allow remote attackers to distinguish valid usernames from invalid ones. The server responds in varying amounts of time when a given username exists, enabling username enumeration through response time analysis. impact: | Attackers can enumerate valid usernames by analyzing server response times, facilitating subsequent brute force or targeted attacks against ProFTPD authentication. remediation: | Upgrade ProFTPD to a version later than 1.2.10 that normalizes response times for authentication attempts regardless of username validity. reference: - http://marc.info/?l=bugtraq&m=109786760926133&w=2 - https://exchange.xforce.ibmcloud.com/vulnerabilities/17724 classification: cvss-metrics: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N cvss-score: 5 cve-id: CVE-2004-1602 cwe-id: CWE-203 epss-score: 0.30679 epss-percentile: 0.9805 cpe: cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:* metadata: verified: true max-request: 1 vendor: proftpd product: proftpd shodan-query: - product:"proftpd" - cpe:"cpe:2.3:a:proftpd:proftpd" tags: cve,cve2004,network,ftp,proftpd,tcp,passive,timing-attack,user-enum,vuln tcp: - inputs: - data: 00000000 type: hex host: - "{{Hostname}}" port: 21 read-size: 1024 matchers: - type: dsl dsl: - "contains(raw, 'ProFTPD')" - "compare_versions(version, '>= 1.2.0', '<= 1.2.10')" condition: and extractors: - type: regex group: 1 name: version regex: - "ProFTPD ([0-9.]+)" # digest: 4a0a004730450221008557bdd1504018ba15922011be77745f2cdcbb003a10e10ba69efe25e532b61d022074e137e451906020166661b7198b5ca6bb276908752cc8dcd8c799a5d02d306d:922c64590222798bb761d5b6d8e72950