Security vulnerability in certain wu-ftpd (and derivitives)

From: suid (suidat_private)
Date: Sun Dec 19 1999 - 17:53:13 PST

  • Next message: Sacha Faust Bourque: "Groupewise Web Interface"

    The following paper is available in full from my website, i have chosen
    not to post the entire thing here as it is quite long.
    
    http://www.suid.edu/advisories/001.txt
    
    suidat_private - the dangers of ftp conversions on misconfigured systems/ftpd (specifically wu-ftpd)
    
    Summary:
    
    	There exists a vulnerability with certain configurations of certain ftp daemons with which users with a valid
    	ftp only acccount on a system may execute arbitrary commands (including binaries supplied by themselves). There
    	also exists the possibilty that anonymous ftp users may execute arbitrary commands (also including binaries
    	supplied by themselves).
    
    	While this vulnerability is entirely configuration dependent. The required configuration is rather common. The
    	requirements can be found in the example exploit section. Usually such misconfigurations are made only by the
    	security-handicapped, and the documentation-illiterate. There is volumous amounts of documentation around which
    	warn against this kind of configuration however it does not touch
    	on this exact problem. Nor does that seem to prevent people from doing
    	this time after time.
    
    
    Regards,
    suidat_private
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:21:58 PDT