2111008 : FTP administrative login attempt detected (FTP_User_Root)

Medium RiskMedium Risk

Quick Links

Event description Jump to the top of this document

An administrative user is attempting to authenticate or has successfully authenticated to use FTP. An attacker who logs in as administrator can view, modify, or delete any file on the system, or execute programs with administrative privileges. This would allow an attacker to perform many malicious actions against the system.

Products that have this security check Jump to the top of this document

FTP_User_Root

This signature detects a user attempting to log in as USER=root, USER=administrator, or USER=admin, or other well known variations of administrator accounts.


Affected platforms Jump to the top of this document

How to remove this vulnerability Jump to the top of this document

Confirm that the FTP session is authorized. Use the time of the FTP session to help determine if this is legitimate administrative activity.

If you suspect that an unauthorized FTP session has occurred, further investigation is warranted. Review the login history of users at the time of the FTP session. It may be necessary to contact any users in question. It is possible that an attacker has gained access to a valid user root FTP account and password. Require the users in question to change their passwords immediately.

References Jump to the top of this document

Information about this document Jump to the top of this document

The information contained in this document may change without notice, and may have been altered or changed if you have received it from a source other than Internet Security Systems. Use of this information constitutes acceptance for use in an "AS IS" condition, without warranties of any kind, and any use of this information is at the user's own risk. Internet Security Systems disclaims all warranties, either expressed or implied, including the warranties of merchantability and fitness for a particular purpose. In no event shall Internet Security Systems be liable for any damages whatsoever, including direct, indirect, incidental, consequential or special damages, arising from the use or dissemination hereof, even if Internet Security Systems has been advised of the possibility of such damages.

Copyright © 1997 – 2009 IBM Internet Security Systems. All rights reserved.

This page was created on Thu Jun 11 09:07:16 2009