Slashdot Mirror


FTP Hacking on the Rise

yahoi writes "The disco-era File Transfer Protocol (FTP) is making a comeback, but not in a good way — spammers are now using the old-school file transfer technology to serve up bot malware, and even as a backdoor into some enterprises that neglect to lock down their oft-forgotten FTP servers. Researchers at F-Secure have spotted a new wave of exploits that use FTP — rather than a malicious URL, or an email attachment — to deliver their malware payloads because few gateways scan for FTP attachments these days."

7 of 212 comments (clear)

  1. FTP through email by whitehatlurker · · Score: 4, Interesting
    This has come full circle - back before internet connectivity was so wide spread, there were a few ftp via email gateways. (Yes, there were other networks alongside the internet.) You'd send your ftp commands and get email back (a few days later or the next week) with the uuencoded result.

    Now you have email viruses delivered via FTP. Cool.

    Yeah I'm old - get off my lawn!

    --
    .. paranoid crackpot leftover from the days of Amiga.
  2. Re:Uh oh by Critical+Facilities · · Score: 2, Interesting

    Yeah, cause no one uses FTP anymore, right?

  3. Re:FTP attachments? by WK2 · · Score: 2, Interesting

    Can anybody translate this into something that makes sense?

    OK. Via spam, F-Secure found a malware web page with an ftp link. They think this is going to be a trend. Some businesses proxy http connections, and scan downloads for viruses. They believe that malware authors will shift away from http to ftp because there is a less likely chance that downloads will be scanned.

    I don't see this happening. It is speculation, and I think malware authors will just use whatever servers they have access to, or whatever they know how to set up. Few organizations scan http or ftp files that go through their gateways.

    To be fair to F-Secure, though, they used tech terms correctly. They properly distinguished between email attachments, http, and ftp. They didn't use the word URL in the entire article. The reporter (or possibly CmdrTaco) likely didn't fully understand what the article says, and thought, "ZOMG!! NEW HAX ATTACKS!! MUST ALERT SLASHDOT!!!"

    --
    Write your own Choose Your Own Adventure. http://www.freegameengines.org/gamebook-engine/
  4. 3rd Party Services by boris111 · · Score: 2, Interesting

    Speaking of FTP I was appalled the other day when my girlfriend told me their small company is paying $100 a month for a service to use FTP for their clients. This service has a space limit of 300 MB!!! With GMAIL and Yahoo email offering unlimited storage this seems unbelievably small.

  5. What the article infers... by johnlcallaway · · Score: 2, Interesting

    It sounds like that 'trusted' sites have been hacked, and that nefarious forces may place files on those trusted sites, then send emails that look authentic. That is, the email looks like it is from a responsible site and has an FTP URL for that site, but the file on the trusted site contains malware of some type.

    I have gotten fake hallmark cards in the past, and only because the URLs were obviously not hallmark did I check the headers. Transform this into a malware that installs a back door, grabs your address book, then sends the address book full of trusted names back to the originator. Now you have an email from a trusted source that has URLs to a trusted site to help spread it.

    Maybe I shouldn't have typed all that out.....

    --
    I rarely read replies, it's my opinion and if you thought about your opinion a little more, I'm OK with that.
  6. I'm a victim by TheGreatOrangePeel · · Score: 2, Interesting

    I fell victim to an FTP security issue in January of last year. The hosting provider for my website allows for anonymous FTP by default and an organization of hackers was able to use this to upload files which somehow enabled them to edit content on my Drupal powered website (I've seen Wordpress sites fall victim to the same hack). All they did was a meta-redirect, but I had about a week of downtime as I restored from dated backups and got technical questions answered on the Drupal.org forums.

    As it turns out, my hosting provider doesn't offer any real real capacity to disable anonymous FTP and I had to set the maximum allowed data transfer amount to 0KB for anyone except myself.

  7. It is a big deal knot. by HTH+NE1 · · Score: 2, Interesting

    Firefox spell-check agrees: two Ns, one L in "tunneling". Further, no ambiguity is introduced by not doubling the L.

    It's a peculiar Americanism. There is robbing, but there's also robing as in the opposite of to disrobe. Raping and rapping are formed from rape and rap respectively, so there's where ambiguity steps in to set the rule. However, it is impelling and not impeling, or even compelling and not compeling. Is it the rule to limit how many repeated adjacent letters you have in a word? There's potterring (Brit.) and pottering (US) but there is only puttering and not putterring anywhere?

    For me, it's trust the spell checker, but when in doubt verify. I'd rather have consistent rules, but English is such a mongrel language anyway, borrowing words everywhere. It's annoying, but at least it isn't annoyying. ;D

    --
    Oh, say does that Star-Spangled Banner entwine / The myrtle of Venus with Bacchus's vine?