Linux TFTP didn't restrict users to tftpboot directory, allowing remote retrieval of files |
---|
Risk Level: | High | Check or Attack Name: LinTftp |
---|---|---|
Platforms: | Linux, TFTP | |
Description: | Some older linux distributions did not correctly limit tftp access to the /tftpboot directory, allowing attackers to retrieve the passwd file as ../etc/passwd. |
|
Remedy: | TFTP is rarely needed in most network configurations and should be disabled. If TFTP is required in your configuration, you should install a more recent version of the daemon or upgrade your OS's distribution. |
|
References: | CERT Advisory CA-91.18, Active Internet tftp Attacks, http://www.cert.org/advisories/CA-91.18.Active.Internet.tftp.Attacks.html |
Know Your Risks |