Bugtraq mailing list archives
Re[2]: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities
From: 3APA3A <3APA3A () SECURITY NNOV RU>
Date: Fri, 2 Feb 2007 23:27:18 +0300
Dear Steven M. Christey, In general case, FTP site admin is not necessary host admin. He can only be allowed to manage users and virtual hosts for FTP. This is privilege escalation vulnerability from FTP site administrator to local system account. In addition, FTP authentication is usually cleartext, and ability to execute code with local system privileges by any FTP account should be taken seriously because of Man-in-the-middle attack vector. -- ~/ZARAZA http://securityvulns.com/ --Friday, February 2, 2007, 10:48:39 PM, you wrote to michal.bucko () hack pl: SMC> Michal, SMC> iFTPAddU is for adding users, and iFTPAddH is for adding virtual SMC> hosts. These sound like administator-level controls. Presumably, the SMC> same admin already had the access to install WS_FTP in the first SMC> place. So, it doesn't seem like these cross any privilege boundaries, SMC> so they don't sound like vulnerabilities. SMC> Am I missing something here? SMC> - Steve
Current thread:
- Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities Steven M. Christey (Feb 02)
- Re[2]: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities 3APA3A (Feb 02)
- <Possible follow-ups>
- Re: Re: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities michal . bucko (Feb 03)
- Re: Re[2]: Ipswitch WS_FTP Server 5.04 multiple arbitrary code execution vulnerabilities ismaelalfaro (Feb 12)