Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Sharp Zaurus Remote FTP Server Root Access Vulnerability

Zaurus is a handheld device distributed by Sharp Electronics.

The FTP daemon used with the Sharp Zaurus to sync the handheld does not require authentication. A remote user with access to the device via the network may log into the device as root without the need for a password. This problem is further compounded by the fact that the FTP daemon binds to all interfaces on the device.







 

Privacy Statement
Copyright 2009, SecurityFocus