Security Information

Security Information  Week 2, 2000

War FTP Daemon is one of the best freeware programs available for running ones own ftp server on Windows NT or Windows 95/98. It is used by several organizations as well as on personal ftp servers, and has achieved high ratings.

5 January 2000 a serious security problem was reported to the author of the program, who a short time later sent out a security alert to the some mailing lists as well as to the War FTP Daemon's newsgroup alt.comp.jgaa. Server administrators were advised to discontinue using the War FTP server until a patch was available.

In less than 24 hours a bugfix for War FTP Daemon version 1.6x was released. A fix for the beta version 1.7x was released a few days later.  These patches may be downloaded from this URL

The security problem had to do with the fact that under certain conditions users could have access to files on the server which they were not supposed to access. This was particularly serious for the beta version 1.7.

We strongly encourage users of the War FTP Daemon to update the server with the appropriate patch.

More information on War FTP Daemon is available from the author's web site.

Per Olav Førland