ignore security and it'll go away

hack_wsftp.txt

hack_wsftp.txt
Posted Aug 17, 1999
Authored by Netherpunk

ws_ftp security design weaknesses allow malicious cracker to take advantage of cached passwords with weak encryption. Remote root compromise possible.

tags | exploit, remote, root
MD5 | 5da15f14ab90f2a47f156373f8992049

hack_wsftp.txt

Change Mirror Download
Hacking WS FTP.INI
------------------


```````````````````````````````````````````````````````````
` ``````````````````````````````````````````````````````` `
` ` ` `
` ` ` `
` ` ` `
` ` ` `
` ` ` `
` ` * ***** *********** ` `
` ` * * * * * ` `
` ` * * * * * ` `
` ` ******* ***** * ` `
` ` * * * * * ` `
` ` * * * * * ` `
` ` * * * * * * *********** * ` `
` ` ` `
` ` http://4n4rchy.hypermart.net ` `
` ` ` `
` ` ` `
` ` ` `
` ` ` `
` ``````````````````````````````````````````````````````` `
```````````````````````````````````````````````````````````
by, Netherpunk, Anarchist Rampage Inc.



I pretty much stumbled onto this bug by myself. Others have probably found it before me, so
I'll let you decide. I actually rewted a few web servers with this thing, so it can be pretty
usefull if you know what you are looking for.

First, most everything that has password options in windows gives you the option to save your
password, usually by checking a check box labeled "save password". Now, being a windows expert
myself, I could say that windows or the program will cache this password in some file very
lightly encrypted. Now this is not only stupid, but it is also a security risk if your
computer is accessable over any network. Never ever save your passwords anywhere. Memorise
them in your head. And also never use the same password for everything.

Now that we know Ws Ftp has the "save password" option, you will want to know where the password
is located. You guessed by the title of the text didn't you? WS_FTP.INI is the file that
stores the ftp sessions that are both default and user defined in Ws Ftp. Now when you open
WS_FTP.INI, you will find normail default settings. Here is an example of the default session to
winsite.com.

[WinSite]
HOST=ftp.winsite.com
UID=anonymous
[Smithsonian Images]
HOST=photo1.si.edu
UID=anonymous
DIR="/images/gif89a/"

Now let us view an example of an ftp session to a sample host with a cached password.

[Primehost]
HOST=sampleftp.host.com
UID=admin
PWD=VE0496D09AC505584A460E9F9B1ABCD9F79A4AB9E9B
PASVMODE=1
TIMEOFFSET=0
LOCDIR=\
rdir0="/"
rdir1="/Backups"
rdir2="/Website"
rdir3="/Website/Common"
ldir0=C:\

Notice the encypted password? Thats what we want to see.

Now that you know what you are looking for, where do you get it and what do you do with it.
Well, as for finding WS_FTP.INI, that is up to you. Some morons upload every file including
WS_FTP.INI to their site. You can also try computers in cyber cafes as well. Now, some might
do things the hard way and try to decrypt the password in some *nix platform. There are c
scripts that do this for .INI files. But what if you are on windows? Get Ws Ftp first of all.
Than copy the session from the victim's .INI and paste it in your own .INI file. Then open
Ws Ftp and connect. That's pretty simple, far to easy for most. Have fun.

This is a big security risk due simply to Ipswitch's lack of effort as far as security is
concerned. Ws Ftp or any FTP program for that matter, can be a big security risk for those who
aren't conscious about it. The bottom line is, never save your passwords. Cached password
files use weak encryption, and in some cases like that of WS_FTP.INI, anyone can use the cached
FTP session.

Happy Hacking!

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

May 2012

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    May 1st
    37 Files
  • 2
    May 2nd
    53 Files
  • 3
    May 3rd
    33 Files
  • 4
    May 4th
    4 Files
  • 5
    May 5th
    10 Files
  • 6
    May 6th
    17 Files
  • 7
    May 7th
    19 Files
  • 8
    May 8th
    36 Files
  • 9
    May 9th
    34 Files
  • 10
    May 10th
    35 Files
  • 11
    May 11th
    20 Files
  • 12
    May 12th
    18 Files
  • 13
    May 13th
    11 Files
  • 14
    May 14th
    27 Files
  • 15
    May 15th
    58 Files
  • 16
    May 16th
    54 Files
  • 17
    May 17th
    25 Files
  • 18
    May 18th
    53 Files
  • 19
    May 19th
    9 Files
  • 20
    May 20th
    15 Files
  • 21
    May 21st
    25 Files
  • 22
    May 22nd
    32 Files
  • 23
    May 23rd
    35 Files
  • 24
    May 24th
    26 Files
  • 25
    May 25th
    25 Files
  • 26
    May 26th
    0 Files
  • 27
    May 27th
    0 Files
  • 28
    May 28th
    0 Files
  • 29
    May 29th
    0 Files
  • 30
    May 30th
    0 Files
  • 31
    May 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2012 Packet Storm. All rights reserved.

close