Access Based Enumeration
Posted: Wed Jun 06, 2018 3:34 am
Hi there,
Currently trialing the software on a VM at the moment as we are considering a migration to Wing FTP from our existing HTTP file server. So far, everything looks good, but I've noticed that when granting the directory 'list' permission to any folder, it means that a user can list all subfolders, even if they do not have access to those folders. Would it be possible to have access based enumeration? A user can only list what they have permissions to?
Currently trialing the software on a VM at the moment as we are considering a migration to Wing FTP from our existing HTTP file server. So far, everything looks good, but I've noticed that when granting the directory 'list' permission to any folder, it means that a user can list all subfolders, even if they do not have access to those folders. Would it be possible to have access based enumeration? A user can only list what they have permissions to?