Check Point Reference: | SBP-2010-24 |
Date Published: | 18 Aug 2010 |
Severity: | High |
Last Updated: | Wednesday 18 August, 2010 |
Source: | |
Industry Reference: | CVE-2009-0542 CVE-2010-2453 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | |
Vulnerability Description | File Transfer Protocol is a popular protocol. FTP server may ask connecting users for their usernames and passwords. While the official FTP specification allows all characters in user names certain FTP servers fail to properly parse FTP usernames that contain special characters, most notably percents and quotes. Since quotes and percents in actual user names are extremely rare it's a good idea to block such characters. |
This protection will detect and block quotes and percents in usernames for FTP login
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: FTP Enforcement Violation.
Attack Information: Suspicious characters in FTP user name