ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Industry watch Toolkit

FTP holes give attackers an easy way in

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 10 Apr 2001 12:34 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A bug in popular software used to transfer files between computers over the Internet could leave a door open to online vandals and network intruders, data protection specialist PGP Security said on Monday.

"In addition to the threat of data loss and attacks against private networks... these vulnerabilities could offer an easy avenue of approach for an attacker intent on defacing Web sites," said Jim Magdych, manager of PGP Security's vulnerability response team.

The vulnerability occurs in a function that allows people accessing a file server to search for particular words, even when they don't know the complete file name. When attackers put in a specially crafted search term, they can cause the computer to execute malicious code, said PGP Security.

Along with HTML -- the lingua franca of the Web -- and email, file transfer protocol, or FTP, is the most common way of moving data across the Web.

According to PGP Security, the flawed FTP server software is part of the standard operating system package from Sun Microsystems, Hewlett-Packard and Silicon Graphics. The FTP software packaged with NetBSD and FreeBSD, two open-source variants of Unix, are also affected, Magdych said.

"FTP has been around a long time, so they use the same root code base," Magdych said.

FTP software has been a common chink in the digital armor that many companies have erected around their networks. Flaws in the free file server created by Washington University, known as wu-FTP, led to a large number of last year's defacements.

While wu-FTP contains the vulnerable function -- known as "glob()" -- it works in a slightly different way with Linux systems, leaving most of those systems protected from the exploit.

The subsidiary of Network Associates announced the most recent flaw on Monday. The company said it had notified software and computer makers that incorporate the vulnerable software in their systems more than two weeks ago and also notified the Computer Emergency Response Team (CERT) at Carnegie Mellon University.

"Ordinarily we might be inclined to hold off a little longer, but we are concerned that information about [the vulnerability] may be starting to circulate," Magdych said.

As of Monday afternoon, however, neither Network Associates nor CERT had an advisory on its Web site.

Systems administrators looking to protect their systems can do so by attacking the root problem, Magdych said.

"To protect yourselves, a quick first step is to make sure that nothing is writable by anonymous FTP users or that those users are not allowed to make a directory," he said.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
36 out of 74 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:












Related Jobs

Risk Director / Project Manager sought ASAP London

If you feel you feel that you have the relevant experience to succeed in such a position, send an up-to-date copy of your resume to Eoin ODonnell, ...

Application Architect - Performance and Capacity Management

AS Delivery offerings are designed to help clients reduce costs while increasing the value of the AD/M function to their enterprise. AS Delivery ...

Commodity Quantitative Developer - Top Investment Bank

If you are an exceptional candidate and you think you could fill this position sen an up to date copy of your resume to Eoin O'Donnell, Head of ...

Featured Talkback

When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal