
Hackers Abuse Zero-Day Exploit for CrushFTP
Source: YouTube · John Hammond · published Apr 26, 2024 · 31:51
A critical vulnerability in Crush FTP (CVE-2024-4044) allows unauthenticated attackers to read arbitrary files and potentially achieve remote code execution 0:00.
Key Takeaways:
• The vulnerability affects Crush FTP versions below 11.1 and is already being actively exploited in the wild since April 19th 0:19
• Discovered by Simon of Airbus CERT, this virtual file system escape allows any arbitrary user to download system files on the host 0:41
• There are an estimated 3,000-6,000 publicly exposed Crush FTP instances vulnerable to this attack 2:00
• The exploit is relatively simple, requiring just a POST request to obtain a session cookie and then using file inclusion syntax to read files 21:50
• Researchers have confirmed the vulnerability can lead to full authentication bypass and remote code execution, making it extremely critical 30:30
This is a high-severity vulnerability requiring immediate patching, especially given its active exploitation in the wild and potential for complete system compromise.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
there is a new vulnerability hit in the streets and being actively exploited in the wild all pertinent to this software called Crush FTP it is a software solution written in Java to offer file transfer services now let me say I'm recording this video on April 23rd and this thing hit the light of day on April 19th when a lot of folks started to chat about it and one of the most I think earliest ones from crowd strike over on their subred noting Crush FTP advised of a virtual file system Escape present in their FTP software that could allow any arbitrary user to download system files on that host and on the endpoint this affects versions of the software Crush FTP below 11.1 and it is just that almost in a sense local file inclusion but we'll pull that thread a little bit further to see how i…