Advertisement
Promo

Industry watch Toolkit

FTP holes give attackers an easy way in

Robert Lemos, ZDNet News ZDNet.co.uk

Published: 10 Apr 2001 12:34 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A bug in popular software used to transfer files between computers over the Internet could leave a door open to online vandals and network intruders, data protection specialist PGP Security said on Monday.

"In addition to the threat of data loss and attacks against private networks... these vulnerabilities could offer an easy avenue of approach for an attacker intent on defacing Web sites," said Jim Magdych, manager of PGP Security's vulnerability response team.

The vulnerability occurs in a function that allows people accessing a file server to search for particular words, even when they don't know the complete file name. When attackers put in a specially crafted search term, they can cause the computer to execute malicious code, said PGP Security.

Along with HTML -- the lingua franca of the Web -- and email, file transfer protocol, or FTP, is the most common way of moving data across the Web.

According to PGP Security, the flawed FTP server software is part of the standard operating system package from Sun Microsystems, Hewlett-Packard and Silicon Graphics. The FTP software packaged with NetBSD and FreeBSD, two open-source variants of Unix, are also affected, Magdych said.

"FTP has been around a long time, so they use the same root code base," Magdych said.

FTP software has been a common chink in the digital armor that many companies have erected around their networks. Flaws in the free file server created by Washington University, known as wu-FTP, led to a large number of last year's defacements.

While wu-FTP contains the vulnerable function -- known as "glob()" -- it works in a slightly different way with Linux systems, leaving most of those systems protected from the exploit.

The subsidiary of Network Associates announced the most recent flaw on Monday. The company said it had notified software and computer makers that incorporate the vulnerable software in their systems more than two weeks ago and also notified the Computer Emergency Response Team (CERT) at Carnegie Mellon University.

"Ordinarily we might be inclined to hold off a little longer, but we are concerned that information about [the vulnerability] may be starting to circulate," Magdych said.

As of Monday afternoon, however, neither Network Associates nor CERT had an advisory on its Web site.

Systems administrators looking to protect their systems can do so by attacking the root problem, Magdych said.

"To protect yourselves, a quick first step is to make sure that nothing is writable by anonymous FTP users or that those users are not allowed to make a directory," he said.

Have your say instantly, and see what others have said. Click on the TalkBack button and go to the Security forum.

Let the editors know what you think in the Mailroom. And read what others have said.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
37 out of 78 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:












Discussions

CA CA

we'll..

Thursday 10 December 2009, 9:55 PM

2 comments
CA CA

Pleasant surprise..

Thursday 10 December 2009, 9:17 PM

2 comments
CA CA

Questions over pub Wi-Fi case remain u...

Thursday 10 December 2009, 9:05 PM

1 comment
lezlow lezlow

brucie baby

Thursday 10 December 2009, 8:33 PM

2 comments
Video icon

Video

Featured Talkback

In association with Network Liberation Movement
When all is said, if Microsoft produce the best product people will buy it and thats a good thing. If people have to buy their product because no one else can produce an alternative, only because interoperability protocols are kept secret, then thats a bad thing.

By: pround

Read full story:
EU court crushes Microsoft's antitrust appeal


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters