Plugin ID | 115 |
Plugin name | Titan FTP Server prior 3.22 CWD heap overflow |
Plugin filename | Titan FTP Server prior 3.22 CWD heap overflow.plugin |
Plugin filesize | 3443 bytes |
Plugin family | FTP |
Plugin created name | Marc Ruef |
Plugin created email | marc dot ruef at computec dot ch |
Plugin created web | http://www.computec.ch |
Plugin created company | computec.ch |
Plugin created date | 2004/09/01 |
Plugin updated name | Marc Ruef |
Plugin updated email | marc dot ruef at computec dot ch |
Plugin updated web | http://www.computec.ch |
Plugin updated company | computec.ch |
Plugin updated date | 2004/11/13 |
Plugin version | 1.1 |
Plugin changelog | Corrected the plugin structure and added the accuracy values in 1.1 |
Plugin protocol | tcp |
Plugin port | 21 |
Plugin procedure detection | open|sleep|close|pattern_exists *220*Titan FTP Server [0-2]* OR *220*Titan FTP Server 3.[0-2]* |
Plugin detection accuracy | 80 |
Plugin comment | This plugin is inspired by the Nessus plugin 14591 and some projects by friends (e.g. BED by Martin J. Münch and Eric Sesterhenn). |
Bug vulnerability class | Buffer Overflow |
Bug description | The target ftp server seems to be running a Titan FTP Server prior 3.22 which is vulnerable to a buffer overflow in the CWD command. This may be used for a denial of service or to run arbitrary code within the context of the server system. An attacker may gain elevated privileges and completely compromise the target host. |
Bug solution | Install the patches for the affected version or upgrade to the latest software version. An Intrusion Prevention System (IPS) may also be able to prevent buffer overflow vulnerabilities as like this one. The ftp server should be deactivated or de-installed if not necessary. To make it harder to find the server the daemon could be configured to listen at another port (e.g. 8021). Try to prevent unwanted connection attempts by filtering traffic with firewalling. Alternation of the application banner can confuse an attacker and let him determine the wrong software. |
Bug fixing time | Approx. 1 hour |
Bug exploit availability | Yes |
Bug exploit url | http://www.snake-basket.de/bed.html |
Bug remote | Yes |
Bug local | Yes |
Bug severity | High |
Bug popularity | 6 |
Bug simplicity | 7 |
Bug impact | 9 |
Bug risk | 7 |
Bug Nessus risk | High |
Bug check tools | Nessus is able to do the same check based on banner-grabbing. See the Nessus plugin ID for more details. Also BED by Eric Sesterhenn and Martin J. Münch can verify/exploit these kinds of overflow vulnerabilities automaticly. |
Source SecurityFocus BID | 11069 |
Source Nessus ID | 14591 |
Source Literature | Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X |
Source Misc. | http://www.computec.ch |