Cyberduck Mountain Duck CLI

#8374 closed enhancement (fixed)

Download without directory listing permission

Reported by: chuckwolber Owned by: dkocher
Priority: normal Milestone: 4.6.4
Component: ftp Version: 4.6
Severity: normal Keywords: anonymous ftp directory listing
Cc: Architecture: Intel
Platform:

Description

A customer has an anonymous FTP site with directory listing turned off in folders that are open for uploading. This enables GPG encrypted files to be placed in an upload folder, such that they are not visible to anyone but an administrator.

Using a command line FTP client (such as ncftp), with knowledge of the exact filename in the upload folder, you can download the file, even though it will not show up in a directory listing of the upload folder. This is useful for giving third parties access to certain named files without advertising the entire directory listing to anyone who connects anonymously.

Cyberduck does not appear to be able to download named files from directories that have directory listing turned off. This would be a very useful feature for customers like mine.

Attachments (2)

cyberduck.png (215.7 KB) - added by chuckwolber on Dec 1, 2014 at 6:57:04 AM.
Cyberduck download attempt triggered from the File - New Download menu item.
commandline.png (160.2 KB) - added by chuckwolber on Dec 1, 2014 at 6:57:42 AM.
Download successfully done via a command line FTP client.

Download all attachments as: .zip

Change History (10)

comment:1 Changed on Nov 26, 2014 at 11:11:32 PM by chuckwolber

  • Summary changed from Anonymous FTP without Directory Listing to Anonymous FTP download without Directory Listing

comment:2 Changed on Nov 27, 2014 at 1:17:22 PM by dkocher

  • Resolution set to worksforme
  • Status changed from new to closed

Changed on Dec 1, 2014 at 6:57:04 AM by chuckwolber

Cyberduck download attempt triggered from the File - New Download menu item.

Changed on Dec 1, 2014 at 6:57:42 AM by chuckwolber

Download successfully done via a command line FTP client.

comment:3 follow-up: Changed on Dec 1, 2014 at 7:00:06 AM by chuckwolber

  • Resolution worksforme deleted
  • Status changed from closed to reopened

I attempted exactly what was suggested with no success. I attached screen shots as proof. I am able to download a file using a command line FTP client. I cannot do the same with cyberduck. You can try it yourself by attempting to download ftp://ftp.idmserv.com/incoming13/alextest

Note that the incoming13 directory has dir listing turned off. I believe this is what is confusing Cyberduck.

Last edited on Dec 1, 2014 at 7:04:33 AM by chuckwolber (previous) (diff)

comment:4 Changed on Dec 1, 2014 at 9:23:00 AM by dkocher

  • Milestone set to 4.7
  • Owner set to dkocher
  • Status changed from reopened to new

comment:5 Changed on Dec 1, 2014 at 9:23:25 AM by dkocher

  • Component changed from core to ftp
  • Status changed from new to assigned
  • Summary changed from Anonymous FTP download without Directory Listing to Download without directory listing permission

comment:6 in reply to: ↑ 3 Changed on Jan 20, 2015 at 3:13:13 PM by dkocher

Replying to chuckwolber:

Note that the incoming13 directory has dir listing turned off. I believe this is what is confusing Cyberduck.

We currently require a directory listing to determine the file size.

comment:7 Changed on Jan 20, 2015 at 3:39:50 PM by dkocher

  • Milestone changed from 4.7 to 4.6.4
  • Resolution set to fixed
  • Status changed from assigned to closed

In r16523. Requires MLST support on the server.

comment:8 Changed on Jan 20, 2015 at 3:51:15 PM by dkocher

Fix for SFTP in r16525.

Note: See TracTickets for help on using tickets.
swiss made software