Zaurus is a handheld device distributed by Sharp Electronics. The FTP daemon used with the Sharp Zaurus to sync the handheld does not require authentication. A remote user with access to the device via the network may log into the device as root without the need for a password. This problem is further compounded by the fact that the FTP daemon binds to all interfaces on the device.
Zaurus is a handheld device distributed by Sharp Electronics. The FTP daemon used with the Sharp Zaurus to sync the handheld does not require authentication. A remote user with access to the device via the network may log into the device as root without the need for a password. This problem is further compounded by the fact that the FTP daemon binds to all interfaces on the device.