Search:     Advanced search
server monitoring

Ariel FTP Server Default document Account

Article ID: 22870
Last updated: 27 Jan, 2009
Views: 411
Posted: 22 Jan, 2009
by: Tech Pubs S.
Updated: 27 Jan, 2009
by: Tech Pubs S.

Ariel FTP Server Default document Account

This script is Copyright (C) 2006-2008 Tenable Network Security, Inc.

FamilyFTP
Plugin ID22870
Bugtraq ID
CVE ID

Description:

Synopsis :

The remote FTP server can be accessed with a known login and password
pair.

Description :

The remote host is an Ariel FTP server.

Ariel is a document transmission system mostly used in the academic
world.

It is possible to log into the remote FTP server by connecting as the
user document (or ariel4) and with a hex-encoded password based on
the IP address of the host the user is connecting from.

An attacker could log into it and obtain the files from the print
queue or use the remote storage space for anything else.

See also :

http://www4.infotrieve.com/products_services/ariel.asp

Solution :

Filter incoming traffic to this port.

Risk factor :

Medium / CVSS Base Score : 6.4
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N)
This article was:   Helpful | Not Helpful
Prev   Next
FTP site exec     Debian proftpd 1.2.0 runs as root