Release of the ProFTPD FTP Server 1.3.8

After two and a half years of development, a significant release of the ProFTPD FTP server 1.3.8 has been published, notable for its extensibility and functionality, but also for the periodic identification of serious vulnerabilities. At the same time, a corrective release ProFTPD 1.3.7f is available, which will be the last in the ProFTPD 1.3.7 series.

Key innovations in ProFTPD 1.3.8:

  • Support for the FTP command CSID (Client/Server ID) has been implemented, which can be used to send information for identifying the client software to the server and receive a response with server identification information. For example, a client can send "CSID Name=BSD FTP; Version=7.3" and receive in response "200 Name=ProFTPD; Version=1.3.8; OS=Ubuntu Linux; OSVer=22.04; CaseSensitive=1; DirSep=/;".
  • The implementation of the SFTP protocol has been enhanced with support for the extension "home-directory" to disclose paths ~/ and ~user/. This can be enabled using the directive "SFTPExtensions homeDirectory."
  • Support for AES-GCM ciphers "aes128-gcm@openssh.com" and "aes256-gcm@openssh.com" has been added to mod_sftp, along with host key rotation ("SFTPOptions NoHostkeyRotation") using OpenSSH extensions "hostkeys-00@openssh.com" and "hostkeys-prove-00@openssh.com." The SFTPCiphers directive has been enhanced to support incorporating AES GCM ciphers.
  • An option "—enable-pcre2" has been added for building with the PCRE2 library instead of PCRE. The RegexOptions directive now allows selection of the regular expression engine between PCRE2, POSIX, and PCRE.
  • The SFTPHostKeys directive has been added to specify the client-offered algorithms for host keys for the mod_sftp module.
  • The FactsDefault directive has been introduced to explicitly define the list of returned "facts" in FTP responses MLSD/MLSD.
  • The LDAPConnectTimeout directive has been added to specify the connection timeout to the LDAP server.
  • The ListStyle directive has been added, allowing the output of directory content lists in Windows style.
  • The RedisLogFormatExtra directive has been implemented to add custom keys and values to the JSON log activated by the RedisLogOnCommand and RedisLogOnEvent directives.
  • The BanOnEvent directive has been enhanced with a MaxLoginAttemptsFromUser parameter to block specified user combinations and (the key to connect to is specified, and iroh finds the associated host and establishes an encrypted connection using the QUIC protocol). Direct P2P connections are established whenever possible, but if not, it falls back to using relays, which are also employed for host discovery by keys. You can run your own relay or connect to public relays supported by the community..
  • The RedisSentinel directive now supports TLS for connections to the Redis database. The RedisServer directive has been enhanced to support the modified syntax of the AUTH command, which has been used since Redis 6.x.
  • The SFTPDigests directive has been enhanced to support ETM (Encrypt-Then-MAC) hashes.
  • The SocketOptions directive now includes the ReusePort flag to enable the SO_REUSEPORT socket mode.
  • The TransferOptions directive now includes the AllowSymlinkUpload flag to restore the ability to upload to symbolic links.
  • The SFTPKeyExchanges directive now supports the key exchange algorithm 'curve448-sha512'.
  • The mod_wrap2 module now allows substitution of additional files in the allow/deny tables.
  • The default value of the FSCachePolicy parameter has been changed to 'off'.
  • The mod_sftp module has been adapted for use with the OpenSSL 3.x library.
  • Support has been added for building with the libidn2 library to use internationalized domain names (IDN).
  • In the ftpasswd utility, the SHA256 algorithm is now enabled by default for generating password hashes instead of MD5.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster