Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Attacks/Breaches

3/11/2008
08:20 AM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

FTP Hacking on the Rise

First it was stolen FTP server admin privileges. Now it's spam messages with bot-infected FTP links

The File Transfer Protocol (FTP) has attracted renewed interest lately, but not in a good way: The bad guys are now using the ‘70s disco-era file transfer technology to serve up bot malware, and even as a backdoor into some enterprises that neglect to lock down their FTP servers.

Researchers at F-Secure have spotted a new wave of exploits that use FTP -- rather than a malicious URL, or the conspicuous email attachment -- to deliver their malware payloads. “As SMTP and HTTP are much better filtered for malware, FTP might be the best transport protocol for a virus writer,” says Mikko Hypponen, chief research officer for F-Secure. “We've just started to observe this phenomenon -- it's not widespread yet, but likely to increase.”

Last month, researchers at Finjan stumbled onto a cache of stolen FTP server administrative credentials that put nearly 9,000 FTP servers at some major global companies at risk, demonstrating just how widespread the old-school FTP remains at many organizations. Cybercriminals were selling a new crimeware package that would automatically infect those servers, some of which were from the world's top 100 domains. (See Stolen FTP Credentials Offered for Sale: Major Firms at Risk.)

F-Secure’s team last week discovered malicious Hallmark greeting card spam messages aimed at recruiting bots. The messages’ links to “view” the greeting instead take the victims to a bot-infected machine serving as an FTP site. The code it downloads is actually a variant of the Zapchast mIRC-bot, according to F-Secure. Instead of receiving the greeting, the user becomes a bot.

So why this retro-borne attack, especially when use of FTP is on the wane? FTP today is often a forgotten or unknown hole in the security of an organization -- not many enterprises bother to monitor it. And for bot herders, it’s just another means of moving malware.

“FTP is more popular than anyone knows -- a lot of people still send FTP stuff back and forth because it’s easy to do,” says Taher Elgamal, CTO of Tumbleweed Communications, which sells secure FTP software. And from the bad guy’s perspective, FTP is less likely to be blocked than an instant message, he says. “FTP is sort of left alone because it’s supposed to be an old thing no one cares about. But it’s an effective protocol for transferring large files... That’s why we’re seeing this [attack] phenomenon.”

Elgamal says the bad guys can hop on Port 80 and ship FTP through that port, for example, and a firewall wouldn’t block the file transfer. Some Internet gateways scan for FTP traffic, such as F-Secure’s Internet Gatekeeper, which does so by default. But many organizations just don’t bother scanning for FTP traffic at all either because they don’t consider it a risk or they don’t realize it’s being used, security experts say.

Still, the FTP-borne attack obviously won’t ever be as big as an HTTP-borne one. “Most companies wouldn't set up a new FTP site any more -- it's so old school. [But] the [FTP] sites that are out there are old and often forgotten about and poorly protected,” F-Secure’s Hypponen says.

Have a comment on this story? Please click "Discuss" below. If you'd like to contact Dark Reading's editors directly, send us a message.

  • F-Secure Corp.
  • Finjan Software Inc.
  • Tumbleweed Communications Corp. (Nasdaq: TMWD)

    Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Newest First  |  Oldest First  |  Threaded View
    DevSecOps: The Answer to the Cloud Security Skills Gap
    Lamont Orange, Chief Information Security Officer at Netskope,  11/15/2019
    Attackers' Costs Increasing as Businesses Focus on Security
    Robert Lemos, Contributing Writer,  11/15/2019
    Human Nature vs. AI: A False Dichotomy?
    John McClurg, Sr. VP & CISO, BlackBerry,  11/18/2019
    Register for Dark Reading Newsletters
    White Papers
    Video
    Cartoon Contest
    Write a Caption, Win a Starbucks Card! Click Here
    Latest Comment: -when I told you that our cyber-defense was from another age
    Current Issue
    Navigating the Deluge of Security Data
    In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
    Flash Poll
    Rethinking Enterprise Data Defense
    Rethinking Enterprise Data Defense
    Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    CVE-2011-3350
    PUBLISHED: 2019-11-19
    masqmail 0.2.21 through 0.2.30 improperly calls seteuid() in src/log.c and src/masqmail.c that results in improper privilege dropping.
    CVE-2011-3352
    PUBLISHED: 2019-11-19
    Zikula 1.3.0 build #3168 and probably prior has XSS flaw due to improper sanitization of the 'themename' parameter by setting default, modifying and deleting themes. A remote attacker with Zikula administrator privilege could use this flaw to execute arbitrary HTML or web script code in the context ...
    CVE-2011-3349
    PUBLISHED: 2019-11-19
    lightdm before 0.9.6 writes in .dmrc and Xauthority files using root permissions while the files are in user controlled folders. A local user can overwrite root-owned files via a symlink, which can allow possible privilege escalation.
    CVE-2019-10080
    PUBLISHED: 2019-11-19
    The XMLFileLookupService in NiFi versions 1.3.0 to 1.9.2 allowed trusted users to inadvertently configure a potentially malicious XML file. The XML file has the ability to make external calls to services (via XXE) and reveal information such as the versions of Java, Jersey, and Apache that the NiFI ...
    CVE-2019-10083
    PUBLISHED: 2019-11-19
    When updating a Process Group via the API in NiFi versions 1.3.0 to 1.9.2, the response to the request includes all of its contents (at the top most level, not recursively). The response included details about processors and controller services which the user may not have had read access to.