bk99.de entertain the web since 1997

Insecure FTP passwords lead to injected PHP scripts

Summary

Manuel Schmitt describes compromised FTP accounts through which attackers uploaded PHP scripts to web hosting accounts. The attackers uploaded PHP scripts through regular FTP users. The hosting provider disabled the accounts, blocked the scripts and informed the affected customers.

Ideas

  • An FTP password identical to the user name offers practically no protection.
  • Valid credentials make malicious uploads look like normal customer actions in the logs.
  • Incident response includes blocking, preserving evidence, informing and cleaning up.
  • Plain-text FTP also increases the risk of intercepted credentials.

Insights

  • Weak tenant accounts create operational work even without a complete server compromise.
  • Logs clarify the access path, but not automatically how a password was lost.

Facts

  • In one case described, the password was exactly the FTP user name.

Recommendations

  • Disable FTP in favour of SFTP or FTPS and enforce strong credentials.
  • Alert on new executable files and unusual upload sources.

References

Read the original article on Hostblogger

Search the Web Archive