home.social

#ws_ftp — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ws_ftp, aggregated by home.social.

fetched live
  1. Angreifer können durch kritische Lücke in WS_FTP Systeme kompromittieren | heise online
    heise.de/-9357127 #WS_FTP #Sicherheitslücke

  2. "🚨 Critical Vulnerabilities Unearthed in WS_FTP Server by Progress Software 🚨"

    Progress Software has issued a warning regarding multiple critical vulnerabilities found in its WS_FTP Server. The vulnerabilities span a range of issues including .NET deserialization, directory traversal, SQL injection, and cross-site scripting, with severity scores ranging from 5.3 (Medium) to a whopping 10.0 (Critical). The most severe among them, CVE-2023-40044 and CVE-2023-42657, could potentially allow attackers to execute remote commands on the WS_FTP Server operating system and perform unauthorized file operations respectively. Progress has rolled out patches to address these vulnerabilities, urging users to upgrade to the latest version, 8.8.2, to safeguard against exploitation.

    The article is penned by Eswar on October 2, 2023, who is known for his engaging cybersecurity content. This discovery sheds light on the importance of regular security audits and timely patch management to thwart potential cyber threats. 🛡️🔐

    Source: GBHackers

    Tags: #CyberSecurity #Vulnerability #WS_FTP #ProgressSoftware #PatchManagement #InfoSec #CVE202340044 #CVE202342657

  3. Blog on #WS_FTP Server updated with attacker behavior Rapid7 IR folks are seeing tonight. Multiple instances of exploitation in the wild all within minutes of one another, all with the same behavior. rapid7.com/blog/post/2023/09/2

  4. Progress has released software updates to address eight vulnerabilities in its WS_FTP Server software that could lead to remote code execution. Vulnerabilities include deserialization, directory traversal, XSS, SQL injection, CSRF and authentication bypass. WS_FTP Server versions before 8.7.4 and 8.8.2 are affected. Users are advised to update ASAP.

    #cybersecurity #progress #ws_ftp

    thehackernews.com/2023/09/prog

  5. Progress Software is having an interesting time. First #MOVEit, now multiple #vulnerability disclosures for their #WS_FTP product. The silver lining here is that it doesn’t look like any of these are known to have been exploited in the wild. (Yet?)

    But out of curiosity, we looked at the Internet exposure of WS_FTP instances with the Ad Hoc Transfer module installed, read about it here ⬇️

    #infosec #securityResearch #CensysResearch #MFT (No, this isn’t MFT but it all feels very…related.)

    censys.com/cve-2023-40044/

  6. Everybody still just talking about #WS_FTP and #CVE_2023_40044 on the birdsite, huh?