Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

FTP:DIRECTORY:DOT-PCT-20-DOT

Severity

Medium

Recommended

No

Category

FTP

Keywords

".%20" Directory

Release Date

2003/04/22

Update Number

1213

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

FTP: ".%20" Directory


This signature detects ".%20" FTP commands sent to FTP/21. The symbol pair %20 (which translates to a space in Web browsers) removes the preceding period, enabling directory traversal. Attackers can be attempting to reveal the full FTP root path.

Extended Description

FTP Serv-U is an internet FTP server from CatSoft. Authenticated users can gain access to the ftproot of the drive where Serv-U FTP has been installed. Users that have read, write, execute and list access in the home directory will have the same permissions to any file which resides on the same partition as the ftproot, once a user is in the home directory they can successfully transfer any files using specially crafted GET requests. All hidden files will be revealed even if the 'Hide hidden files' feature is on. Successful exploitation of this vulnerability could enable a remote user to gain access to systems files, password files, etc. This could lead to a complete compromise of the host.

Affected Products

  • Cat Soft Serv-U 2.4.0
  • Cat Soft Serv-U 2.5.0

References

  • BugTraq: 2052
  • CVE: CVE-2001-0054
  • URL: http://archives.neohapsis.com/archives/win2ksecadvice/2000-q4/0110.html

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out