235
Cat Soft Serv-U FTP Server Default Administration Account Vulnerability
FTP
2004/09/13
Nico 'Triplex' Spicher
Triplex at IT-Helpnet dot de
http://triplex.it-helpnet.de
http://www.it-helpnet.de
Nico 'Triplex' Spicher
Triplex at IT-Helpnet dot de
http://triplex.it-helpnet.de
http://www.it-helpnet.de
2004/11/13
1.1
Corrected the plugin structure and added the accuracy values in 1.1
tcp
21
open|sleep|send USER LocalAdministrator\n|sleep|send PASS #l@$ak#.lk;0@P\n|send list\n|sleep|close|pattern_exists 150
98
This plugin was written with the ATK-Plugin-Creator [http://triplex.it-helpnet.de].
aT4r ins4n3
at4r@ciberdreams.com
2004/08/08
http://securityfocus.com/bid/10886/info/
Cat Soft Serv-U FTP Server 3.0 to 5.2
Configuration
It is reported that the RhinoSoft Serv-U FTP server has a default administration account that is used to authenticate to the site maintenance interface. The weak account can be used to log into the site maintenance interface on the loopback interface only, and to create user accounts.
If the ftp server is not used it should be de-installed or de-activated. Install the newest patch or bugfix to solve the problem or upgrade to the latest software version which is not vulnerable anymore. Additionally limit unwanted connections and communications with firewalling.
Approx. 20 minutes
Yes
http://downloads.securityfocus.com/vulnerabilities/exploits/servulocal.c
No
Yes
Medium
2
5
8
1
10886
Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X
http://www.computec.ch