Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Security Best Practice: Suspicious Characters in FTP User Name

Subscribe

Check Point Reference: SBP-2010-24
Date Published:
Severity:
Source: Check Point Vulnerability Discovery Team
Industry Reference(s): CVE-2010-0542
Protection Provided by: Security Gateway
  • R71
  • R70
VPN-1
  • NGX R65
VSX
  • NGX R65
Who is Vulnerable?
FTP Servers
Vulnerability Description
File Transfer Protocol is a popular protocol. FTP server may ask connecting users for their usernames and passwords. While the official FTP specification allows all characters in user names certain FTP servers fail to properly parse FTP usernames that contain special characters, most notably percents and quotes. Since quotes and percents in actual user names are extremely rare it's a good idea to block such characters.
Vulnerability Details
A remote command injection vulnerability has been discovered in Synology Disk Station. The Synology Disk Station is a product designed for storage purposes of small offices or home users. It supports several terabytes of total storage. The vulnerability is due to insufficient validation by Disk Station web interface when handling a malformed login command. Remote attackers could exploit this vulnerability by sending a specially crafted login command to a vulnerable system. Successful exploitation would allow the attacker to execute arbitrary commands on the affected system.

Protection Overview
This protection will detect and block suspicious characters in usernames for FTP login requests.

In order for the protection to be activated, update your Security Gateway/VPN-1 product to the latest IPS/SmartDefense update. For information on how to update IPS/SmartDefense, go to SBP-2006-05Protection tab and select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

Security Gateway: R70/R71

How Can I Protect My Network?
1. In the IPS tab, click Protections > By Protocol > Application Intelligence > FTP.
2. In the right pane, double-click the Suspicious Characters in FTP User Name protection.
3. In the Protection Details window, click on Edit. Choose the protection's Action (Override IPS Policy with: Prevent/Detect), and apply Additional Settings
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries: 

Attack Name: FTP Enforcement Violation
Attack Information: Suspicious characters in FTP user name

VPN-1 NGX R65 & VSX NGX R65

How Can I Protect My Network?
1. In the SmartDefense tab, click Application Intelligence > FTP > Suspicious Characters in FTP User Name.
2. In the configuration pane, under Settings > Mode, check Active.
3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries: 

Attack Name: FTP Enforcement Violation
Attack Information: Suspicious characters in FTP user name