FTP CWD ~root login |
---|
Risk Level: | High | Check or Attack Name: ftpcd |
---|---|---|
Platforms: | FTP | |
Description: | Very old versions of the FTP daemon contained a bug that allowed a malicious user to issue a "CWD ~root" command that would result in the attacker gaining root privileges on the system. |
|
Remedy: | Replace the vulnerable FTP daemon with a more recent package, like wuftpd. FTP daemons that are vulnerable to this attack shipped with older distributions of OS's. You should upgrade to the latest OS supported by your hardware.. |
|
References: | CERT Advisory CA-88.01, ftpd vulnerability, http://www.cert.org/advisories/CA-88.01.ftpd.hole.html |
Know Your Risks |