WarFTPd Multiple Macro Vulnerabilities
BID:919
Info
WarFTPd Multiple Macro Vulnerabilities
| Bugtraq ID: | 919 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jan 06 2000 12:00AM |
| Updated: | Jan 06 2000 12:00AM |
| Credit: | Posted to Bugtraq by Sir Dystic of the cDc <[email protected]> on January 5 2000. |
| Vulnerable: |
Jgaa WarFTPd 1.70 b Jgaa WarFTPd 1.67 b2 |
| Not Vulnerable: | |
Discussion
WarFTPd Multiple Macro Vulnerabilities
WarFTPd ships with various macros to assist in the setup of complex FTP sites.
It is possible to call these macros remotely, some of which can be used to compromise the server. Some of these macros will give out server and operating system information, and can be used to reveal the contents of files in error messages, including the configuration files for WarFTP which can include plaintext administrator passwords.
The extent of the vulnerability differs between versions of WarFTPd:
Version 1.67b2 and prior:
Authenticated users can gain access to restricted files.
Version 1.70:
Remote attackers can gain access to any file on the system, as well as run any system command with administrative priveleges if an ODBC driver is installed. This can be done without needing to be logged into the FTP server.
WarFTPd ships with various macros to assist in the setup of complex FTP sites.
It is possible to call these macros remotely, some of which can be used to compromise the server. Some of these macros will give out server and operating system information, and can be used to reveal the contents of files in error messages, including the configuration files for WarFTP which can include plaintext administrator passwords.
The extent of the vulnerability differs between versions of WarFTPd:
Version 1.67b2 and prior:
Authenticated users can gain access to restricted files.
Version 1.70:
Remote attackers can gain access to any file on the system, as well as run any system command with administrative priveleges if an ODBC driver is installed. This can be done without needing to be logged into the FTP server.
Exploit / POC
WarFTPd Multiple Macro Vulnerabilities
execute "literal [filename]"
you will get the error:
500 'file contents' : command not understood
execute "literal [filename]"
you will get the error:
500 'file contents' : command not understood
Solution / Fix
WarFTPd Multiple Macro Vulnerabilities
Solution:
Patches have been provided for both v1.70 and v1.67b2 or older, available at:
http://war.jgaa.com/alert/files
and
ftp://ftp.no.jgaa.com/
Solution:
Patches have been provided for both v1.70 and v1.67b2 or older, available at:
http://war.jgaa.com/alert/files
and
ftp://ftp.no.jgaa.com/
References
WarFTPd Multiple Macro Vulnerabilities
References:
References:
- Jgaa Support Site (Jgaa)
- SECURITY ALERT - WAR FTP DAEMON ALL VERSIONS (Jgaa)
- WarFTP Homepage (Jgaa)