Quelle:
Metasploit Framework ist um einen weiteren Exploit reicher.
This module exploits a directory traversal vulnreability in the XCRC
command implemented in versions of Titan FTP up to and including
8.10.1125. By making sending multiple XCRC command, it is possible
to disclose the contents of any file on the drive with a simple CRC
“brute force” attack. Although the daemon runs with SYSTEM
privileges, access is limited to files that reside on the same drive
as the FTP server’s root directory.
(weiterlesen…)