Short Name |
FTP:OVERFLOW:PASSWORD-BO |
|---|---|
Severity |
High |
Recommended |
Yes |
Recommended Action |
Drop |
Category |
FTP |
Keywords |
8375 Metasploit FTP Password Oracle9i XDB |
Release Date |
2010/04/14 |
Update Number |
1655 |
Supported Platforms |
idp-4.0+, isg-3.4+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+ |
This signature detects attempts to exploit a known vulnerability in some FTP Servers. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the server.
In a paper titled "Variations in exploit methods between Linux and Windows" presented at Blackhat 2003, David Litchfield has illustrated multiple vulnerabilities in the Oracle 9i XML Database (XDB). Successful exploits may allow remote attackers to run arbitrary code in the security context of the vulnerable service.