212
Cat Soft Serv-U FTP server prior 2.5i CWD ..%20 directory traversal
FTP
2004/09/13
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
Marc Ruef
marc dot ruef at computec dot ch
http://www.computec.ch
computec.ch
2004/11/13
1.1
Corrected the plugin structure and added the accuracy values in 1.1
tcp
21
open|sleep|close|pattern_exists 220 Serv-U FTP-Server v2.[0-5]* OR *to /..* OR *to /[a-z]:/* OR *550 /[a-z]:/.*
99
This plugin may be very accurate if not just the banner is analyzed.
Zoa_Chien
zoachien at securax dot org
http://www.securax.org
securax.org
2000/12/05
http://www.securityfocus.com/archive/1/148905
Serv-U FTP server prior 2.5i
Serv-U FTP server newer than 2.5i or other ftp servers
Directory Traversal
The Serv-U FTP server is a well-known ftp server for Windows operating systems. It is possible to break out of the remoteFTP chroot by appending %20s in the CWD command.
If the ftp server is not used it should be de-installed or de-activated. Install the newest patch or bugfix to solve the problem or upgrade to the latest software version which is not vulnerable anymore. Additionally limit unwanted connections and communications with firewalling.
Approx. 20 minutes
Yes
http://www.securityfocus.com/bid/2052/exploit/
Yes
Yes
Medium
7
8
8
7
High
Nessus is able to same check. The attack is very well documented in the original Bugtraq posting.
CVE-2001-0054
2052
10565
Hacking Exposed: Network Security Secrets & Solutions, Stuart McClure, Joel Scambray and George Kurtz, February 25, 2003, 4th Edition, McGraw-Hill Osborne Media, ISBN 0072227427
http://www.securityfocus.com/archive/1/149180