FTP CWD ~root login

Risk Level: High risk vulnerability  High

Check or Attack Name: ftpcd

Platforms: FTP
Description:

Very old versions of the FTP daemon contained a bug that allowed a malicious user to issue a "CWD ~root" command that would result in the attacker gaining root privileges on the system.

Remedy:

Replace the vulnerable FTP daemon with a more recent package, like wuftpd. FTP daemons that are vulnerable to this attack shipped with older distributions of OS's. You should upgrade to the latest OS supported by your hardware..

References:

CERT Advisory CA-88.01, ftpd vulnerability, http://www.cert.org/advisories/CA-88.01.ftpd.hole.html


X-Force Logo
Know Your Risks