File: 1779.txt

package info (click to toggle)
snort 2.3.3-11
  • links: PTS
  • area: main
  • in suites: etch, etch-m68k
  • size: 22,512 kB
  • ctags: 11,344
  • sloc: ansic: 70,967; sh: 4,848; makefile: 748; perl: 478; sql: 212
file content (57 lines) | stat: -rw-r--r-- 1,437 bytes parent folder | download | duplicates (8)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
Rule:

--
Sid:
1779

--
Summary:
This event is generated when an attempt is made to exploit a directory traversal vulnerability associated with the Shambala FTP server. 

--
Impact:
Information disclosure.  A successful attack may permit the navigation of directories and the viewing of files. 

--
Detailed Information:
The Shambala FTP server may be susceptible an a directory traversal attack that permits the navigation and viewing of files in directories other than the intended FTP server's root directory. This exploit is conducted by executing the FTP command "CWD ..." or "cd ...".  This may possibly permit the identification and the viewing of files containing sensitive information.

--
Affected Systems:
Shambala 4.5 FTP server running on Windows 95, 98, NT, and Windows 2000.

--
Attack Scenarios:
An attacker may attempt to exploit this vulnerability to identify and view files on the vulnerable FTP server. 


--
Ease of Attack:
Simple.  

--
False Positives:
None Known.

--
False Negatives:
None Known.

--
Corrective Action:
Upgrade to the latest non-affected version or restrict anonymous FTP user access by assigning appropriate file permissions.

--
Contributors:
Sourcefire Research Team
Brian Caswell <bmc@sourcefire.com> 
Nigel Houghton <nigel.houghton@sourcefire.com>
Judy Novak <judy.novak@sourcefire.com>

--
Additional References:

Miscellaneous:
http://www.securiteam.com/windowsntfocus/5SP011P4KC.html

--