Security error

  • Hi,

    My name Matt. I have found (probably) very critical security error :)

    The fault is not encrypt FTP user password. How check it? Very simply :)

    After loggin to phpMyAdmin (from root or other user from admin access), and go to imscp database, and go to frp_user table. Then you'll see a column rawpassword from password

    I do not know if this is an error, but I wanted to report it :)

    Edited once, last by DukaN ().

  • Hi Matt,

    thanks for report, this is ofcourse known to us and was a workaround for the web ftp client. also mail_users are not crypted of similar reason. it will be fixed some time.

  • Thank you for your response :)

    Topic to close
