The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.
Link | Tags |
---|---|
http://archives.neohapsis.com/archives/bugtraq/2000-06/0282.html | vendor advisory mailing list |
http://www.iss.net/security_center/static/4793.php | vdb entry |