235 Cat Soft Serv-U FTP Server Default Administration Account Vulnerability FTP 2004/09/13 Nico 'Triplex' Spicher Triplex at IT-Helpnet dot de http://triplex.it-helpnet.de http://www.it-helpnet.de Nico 'Triplex' Spicher Triplex at IT-Helpnet dot de http://triplex.it-helpnet.de http://www.it-helpnet.de 2004/11/13 1.1 Corrected the plugin structure and added the accuracy values in 1.1 tcp 21 open|sleep|send USER LocalAdministrator\n|sleep|send PASS #l@$ak#.lk;0@P\n|send list\n|sleep|close|pattern_exists 150 98 This plugin was written with the ATK-Plugin-Creator [http://triplex.it-helpnet.de]. aT4r ins4n3 at4r@ciberdreams.com 2004/08/08 http://securityfocus.com/bid/10886/info/ Cat Soft Serv-U FTP Server 3.0 to 5.2 Configuration It is reported that the RhinoSoft Serv-U FTP server has a default administration account that is used to authenticate to the site maintenance interface. The weak account can be used to log into the site maintenance interface on the loopback interface only, and to create user accounts. If the ftp server is not used it should be de-installed or de-activated. Install the newest patch or bugfix to solve the problem or upgrade to the latest software version which is not vulnerable anymore. Additionally limit unwanted connections and communications with firewalling. Approx. 20 minutes Yes http://downloads.securityfocus.com/vulnerabilities/exploits/servulocal.c No Yes Medium 2 5 8 1 10886 Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X http://www.computec.ch