115 Titan FTP Server prior 3.22 CWD heap overflow FTP 2004/09/01 Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch Marc Ruef marc dot ruef at computec dot ch http://www.computec.ch computec.ch 2004/11/13 1.1 Corrected the plugin structure and added the accuracy values in 1.1 tcp 21 open|sleep|close|pattern_exists *220*Titan FTP Server [0-2]* OR *220*Titan FTP Server 3.[0-2]* 80 This plugin is inspired by the Nessus plugin 14591 and some projects by friends (e.g. BED by Martin J. Münch and Eric Sesterhenn). Buffer Overflow The target ftp server seems to be running a Titan FTP Server prior 3.22 which is vulnerable to a buffer overflow in the CWD command. This may be used for a denial of service or to run arbitrary code within the context of the server system. An attacker may gain elevated privileges and completely compromise the target host. Install the patches for the affected version or upgrade to the latest software version. An Intrusion Prevention System (IPS) may also be able to prevent buffer overflow vulnerabilities as like this one. The ftp server should be deactivated or de-installed if not necessary. To make it harder to find the server the daemon could be configured to listen at another port (e.g. 8021). Try to prevent unwanted connection attempts by filtering traffic with firewalling. Alternation of the application banner can confuse an attacker and let him determine the wrong software. Approx. 1 hour Yes http://www.snake-basket.de/bed.html Yes Yes High 6 7 9 7 High Nessus is able to do the same check based on banner-grabbing. See the Nessus plugin ID for more details. Also BED by Eric Sesterhenn and Martin J. Münch can verify/exploit these kinds of overflow vulnerabilities automaticly. 11069 14591 Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, Düsseldorf, ISBN 381582284X http://www.computec.ch