Bug in MS FTP 4.0

From: Geoffrey Cleaves (Geoffrey.Cleavesat_private)
Date: Wed Jun 16 1999 - 13:41:35 PDT

  • Next message: Simple Nomad: "Linux/Netware Access"

    Could somebody please corroborate a bug that has been giving me problems and
    I believe could be a security concern:
    
    With a password that allows deleting and downloading, I have been able to
    make files located on the FTP Server Version 4.0 undeletable except by
    restarting the server (according to my wonderful IT department).  What I do
    is very simple.  Using a client, I start downloading any file and while that
    is taking place, I delete the same from the server also using the client.
    The log tells me the delete is successful, but when refreshing the server
    the file is still there.  When trying to delete the file again I get a
    message saying Access Denied.  Remember, I have delete authority.
    
    When I call my brilliant IT department that administers the server they tell
    me the file does not exist.  Apparently, it is not on the hard drive but
    still in memory and can still be downloaded via FTP (just not deleted).
    Wouldn't this mean that somebody could repeat what I have done continuously
    until the memory is full and bring the server down?
    
    Thanks for any help and before responding, please read my Apologies Section.
    
    APOLOGIES
    I know this list is meant for Unix issues, but I have seen many Microsoft
    related posts.
    This is my first post ever to this sort of list, so sorry if it was done
    poorly.
    I searched for the above described error in you archives and other places
    before posting.  Sorry if this is old news.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 14:50:03 PDT