|
2111008 : FTP administrative login attempt detected (FTP_User_Root) |
|
Quick Links
- Event Description
- Products that have this security check
- Affected platforms
- How to remove this vulnerability
- References
- Information about this document
An administrative user is attempting to authenticate or has successfully authenticated to use FTP. An attacker who logs in as administrator can view, modify, or delete any file on the system, or execute programs with administrative privileges. This would allow an attacker to perform many malicious actions against the system.
Products that have this security check
![]()
- BlackICE Agent for Server
- BlackICE PC Protection
- BlackICE Server Protection
- Proventia Desktop
- Proventia Network IDS
- Proventia Network IPS
- Proventia Network MFS
- Proventia Server IPS for Linux technology
- Proventia Server IPS for Microsoft Windows technology
- RealSecure Desktop
- RealSecure Desktop Protector 3.6
- RealSecure Network
- RealSecure Server Sensor
| FTP_User_Root | |
This signature detects a user attempting to log in as USER=root, USER=administrator, or USER=admin, or other well known variations of administrator accounts. |
- IETF FTPVarious vendors Any operating system
How to remove this vulnerability
![]()
Confirm that the FTP session is authorized. Use the time of the FTP session to help determine if this is legitimate administrative activity.
If you suspect that an unauthorized FTP session has occurred, further investigation is warranted. Review the login history of users at the time of the FTP session. It may be necessary to contact any users in question. It is possible that an attacker has gained access to a valid user root FTP account and password. Require the users in question to change their passwords immediately.
Information about this document
![]()
The information contained in this document may change without notice, and may have been altered or changed if you have received it from a source other than Internet Security Systems. Use of this information constitutes acceptance for use in an "AS IS" condition, without warranties of any kind, and any use of this information is at the user's own risk. Internet Security Systems disclaims all warranties, either expressed or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Internet Security Systems be liable for any damages whatsoever, including direct, indirect, incidental, consequential or special damages, arising from the use or dissemination hereof, even if Internet Security Systems has been advised of the possibility of such damages.
Copyright © 1997 – 2009 IBM Internet Security Systems. All rights reserved.
This page was created on Thu Jun 11 09:07:16 2009
