Insecure FTP passwords lead to injected PHP scripts
Summary
Manuel Schmitt describes compromised FTP accounts through which attackers uploaded PHP scripts to web hosting accounts. The attackers uploaded PHP scripts through regular FTP users. The hosting provider disabled the accounts, blocked the scripts and informed the affected customers.
Ideas
- An FTP password identical to the user name offers practically no protection.
- Valid credentials make malicious uploads look like normal customer actions in the logs.
- Incident response includes blocking, preserving evidence, informing and cleaning up.
- Plain-text FTP also increases the risk of intercepted credentials.
Insights
- Weak tenant accounts create operational work even without a complete server compromise.
- Logs clarify the access path, but not automatically how a password was lost.
Facts
- In one case described, the password was exactly the FTP user name.
Recommendations
- Disable FTP in favour of SFTP or FTPS and enforce strong credentials.
- Alert on new executable files and unusual upload sources.
References
Read the original article on Hostblogger
Links to the original source and the Web Archive open in a new tab.