CVE-2010-3187
published 2010-08-30CVE-2010-3187: Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.
PriorityP264critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
20.03%
97.2th percentile
Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | aix | <= 5.3 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Flag use of the anonymous/guest FTP credential 'ftp' / '[email protected]' as a potential exploit attempt indicator. ↗
- ·The exploit targets IBM AIX 5.1, 5.2, and 5.3 (and possibly 4.x); the '-s' flag in the advanced exploit switches from NLST to LIST command for AIX 5.3 compatibility. ↗
- ·The core dump file is described as 'scrambled'; analysts must search for 13-character DES-looking strings within it to extract password hashes. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id ASCII"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"ASCII("; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005168; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id INSERT"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"INSERT"; nocase; content:"INTO"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005166; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UPDATE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UPDATE
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UPDATE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UPDATE"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"UPDATE"; nocase; content:"SET"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005169; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id SELECT
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id SELECT"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"SELECT"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005164; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id DELETE
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id DELETE
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id DELETE
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id DELETE"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"DELETE"; nocase; content:"FROM"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005167; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_i
Suricata
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UNION SELECT
suricata·2010-07-30·CVSS 7.5
CVE-2007-0566 [HIGH] ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UNION SELECT
ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UNION SELECT
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET WEB_SPECIFIC_APPS ASP NEWS SQL Injection Attempt -- news_detail.asp id UNION SELECT"; flow:established,to_server; http.uri; content:"/news_detail.asp?"; nocase; content:"id="; nocase; content:"UNION"; nocase; content:"SELECT"; nocase; distance:0; reference:cve,CVE-2007-0566; reference:url,www.milw0rm.com/exploits/3187; classtype:web-application-attack; sid:2005165; rev:9; metadata:affected_product Web_Server_Applications, attack_target Web_Server, created_at 2010_07_30, deployment Datacenter, confidence Medium, signature_severity Major, tag SQL_Injection, updated_at 2020_09_10, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitr
Exploit-DB
IBM AIX 5l - 'FTPd' Remote DES Hash
exploitdb·2010-07-24
CVE-2010-3187 IBM AIX 5l - 'FTPd' Remote DES Hash
IBM AIX 5l - 'FTPd' Remote DES Hash
---
/*
* IBM AIX 5l FTPd Remote DES Hash Exploit -- Advanced 'Datacenter' Edition :>
*
* Should work on IBM AIX 5.1,5.2,5.3! probably on 4.X too
*
* bug found & exploited by Kingcope
*
* Version 2.0 - July 2010
* ----------------------------------------------------------------------------
* Description: -
* The AIX 5l FTP-Server crashes when an overly long NLST command is supplied -
* For example: NLST ~AAAAA...A (2000 A´s should be enough) -
* The fun part here is that it creates a coredump file in the current -
* directory if it is set writable by the logged in user. -
* The goal of the exploit is to get the DES encrypted user hashes -
* off the server. These can be later cracked with JtR. -
* This is accomplished by populating the memory with logins
Exploit-DB
AIX5l with FTP-Server - Hash Disclosure
exploitdb·2010-07-18
CVE-2010-3187 AIX5l with FTP-Server - Hash Disclosure
AIX5l with FTP-Server - Hash Disclosure
---
### AIXCOREDUMP.PL ---
### --== ~ AIX5l w/ FTP-SERVER REMOTE ROOT HASH DISCLOSURE EXPLOIT ~ =--
### CREATES COREDUMP INCLUDING THE ROOT USER HASH FROM /etc/security/passwd
### THE RESULT FILE IS SCRAMBLED - SEEK FOR DES LOOKING CRYPTO KEYS
### SUCCESSFULLY TESTED ON IBM AIX 5.1
### DISCOVERED & EXPLOITED BY KINGCOPE
### JULY 2010
use IO::Socket;
$|=1;
print "--== ~ AIX5l w/ FTP-SERVER REMOTE ROOT HASH DISCLOSURE EXPLOIT ~ =--\n";
print "CREATES COREDUMP INCLUDING THE ROOT USER HASH FROM /etc/security/passwd\n";
print "BY KINGCOPE\n";
print "JULY 2010\n\n";
if ($#ARGV [username] [password]\n";
print "SAMPLES:\n";
print "YOU HAVE A LOGIN ./AIXCOREDUMP.PL 192.168.1.150 192.168.1.25 kcope passwd\n";
print "USE GUEST ACCOUNT - NEEDS WRITE ACCESS
No writeups or analysis indexed.
http://aix.software.ibm.com/aix/efixes/security/ftpd_advisory.aschttp://seclists.org/fulldisclosure/2010/Jul/281http://seclists.org/fulldisclosure/2010/Jul/317http://seclists.org/fulldisclosure/2010/Jul/324http://seclists.org/fulldisclosure/2010/Jul/337http://securitytracker.com/id?1024368http://www.exploit-db.com/exploits/14409/http://www.exploit-db.com/exploits/14456/http://www.ibm.com/support/docview.wss?uid=isg1IZ83252http://www.ibm.com/support/docview.wss?uid=isg1IZ83274http://www.ibm.com/support/docview.wss?uid=isg1IZ83275http://www.ibm.com/support/docview.wss?uid=isg1IZ83276http://www.osvdb.org/66576https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11697http://aix.software.ibm.com/aix/efixes/security/ftpd_advisory.aschttp://seclists.org/fulldisclosure/2010/Jul/281http://seclists.org/fulldisclosure/2010/Jul/317http://seclists.org/fulldisclosure/2010/Jul/324http://seclists.org/fulldisclosure/2010/Jul/337http://securitytracker.com/id?1024368http://www.exploit-db.com/exploits/14409/http://www.exploit-db.com/exploits/14456/http://www.ibm.com/support/docview.wss?uid=isg1IZ83252http://www.ibm.com/support/docview.wss?uid=isg1IZ83274http://www.ibm.com/support/docview.wss?uid=isg1IZ83275http://www.ibm.com/support/docview.wss?uid=isg1IZ83276http://www.osvdb.org/66576https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11697
2010-08-30
Published