ProFTPD 1.3.5 Mod_Copy Command Execution

Discussion in 'News Aggregator' started by Packet Storm, 10 Jun 2015.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits the SITE CPFR/CPTO commands in ProFTPD version 1.3.5. Any unauthenticated client can leverage these commands to copy files from any part of the filesystem to a chosen destination. The copy commands are executed with the rights of the ProFTPD service, which by default runs under the privileges of the 'nobody' user. By using /proc/self/cmdline to copy a PHP payload to the website directory, PHP remote code execution is made possible.

    Continue reading...
     

Share This Page

Loading...