Skip to main content

Broken Clients Compatibility - FTP Issue

Comments

4 comments

  • cPanelMichael
    Hello :) I have moved this thread to our "Security" sub-forum for discussion of any potential security impact when enabling this option. Note that I checked Pure-FTP's documentation, but I was unable to find any details on the exact changes enacted when enabling this option. Thank you.
    0
  • hostkingco
    Anyone have any idea yet if there are any security risks with this option enabled?
    0
  • PbG
    I am wondering this as well. Researching exactly what protocols are ignored with this option enabled are how I found this thread. I don't know why cPanel does not publish this information with the option?
    0
  • cPMelaniel
    'Broken Clients Compatibility' is an option provided from Pure-FTP and not directly from cPanel. I was unable to locate any documentation regarding the option, however there is a discussion on the mailing list of what the configuration actually does. [url=http://marc.info/?l=pureftpd-list&m=126044538824016]'Re: [pure-ftpd] Question for "BrokenClientsCompatibility yes"' - MARC - Symbolic links are made up as real files or directories - The server insists on entering a password even when there's none for the anonymous user. - When there's no anonymous account, instead of replying "this account doesn't exist" when the client tries to use it, the server replies "of course it exists, go ahead" and then replies "oops no sorry it doesn't exist" after the next step, when a dummy password is received. This stupid behavior was required prior to IE8. - EPSV is disabled. If you are looking for further information regarding the option or the particular security issues or dangers, you may wish to contact Pure-FTP directly. I hope this helps! Thank you!
    0

Please sign in to leave a comment.