OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Subject: Re: WuFTPD: Providing *remote* root since at least1994
From: Gregory A Lundberg (lundbergVR.NET)
Date: Tue Jun 27 2000 - 17:48:59 CDT


On Tue, Jun 27, 2000 at 05:29:43PM +0200, Tomasz Grabowski wrote:

> Anyway I made a patch for that bug so You don't need to change Your
> wu-ftpd-academ to wu-ftpd if You don't want.

Bascially, all your patch does is prevent an attack which isn't (currently)
being used very widely on a version of the server which is vulnerable to at
least two attacks which ARE.

The smart thing to do is immedeately disconnect your 'wu-ftpd-academ' host
and scan for root breakins. Then, when you've cleaned out the kiddies and
regained control of your host, upgrade to 2.6.0 and apply the patch.

--

Gregory A Lundberg WU-FTPD Development Group 1441 Elmdale Drive lundbergwu-ftpd.org Kettering, OH 45409-1615 USA 1-800-809-2195