[NT] Total Commander WCX_FTP.INI FTP Account Information Weak Encryption



The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html

- - - - - - - - -



Total Commander WCX_FTP.INI FTP Account Information Weak Encryption
------------------------------------------------------------------------


SUMMARY

" <http://www.ghisler.com/> Total Commander is a file manager for Windows,
a program like Windows Explorer to copy, move or delete files. However,
Total Commander can do much more than Explorer, e.g. pack and unpack
files, access ftp servers, compare files by content, etc"

" <http://securityresponse.symantec.com/avcenter/venc/data/w32.gudeb.html>
W32.Gudeb is a worm that lowers security settings and hides folders on the
compromised computer. It spreads via FTP and gathers valid accounts from
Total Commander configuration file."

Weak password storage by Total Commander's settings file, allows local
attackers and Worms to gain FTP login information and compromise other
systems.

DETAILS

Vulnerable Systems:
* Total Commander version 6.53

Total Commander file manager/FTP client utility is confirmed as affected
to weak account information encryption vulnerability. The vulnerability is
caused due to weak encryption algorithm used when internal FTP account
information is saved to the configuration file WCX_FTP.INI. Both username
and password are saved to the file located at directory from %System%
variable.

This is reportedly being exploited by a new W32.Gudeb worm. W32.Gudeb
spreads via FTP and gathers valid accounts from Total Commander
configuration file. This malware searches for the file
%System%\WCX_FTP.INI and gathers valid username and password details. If
this operation is successful, it will reportedly upload a copy of itself
to the newly compromised computers.

Example:
C:\WINNT\wcx_ftp.ini:
---clip---
[OldConnections]
0=ftp.removed.com
[connections]
1=Homepage
[Homepage]
host=ftp.removed.com
username=www.removed.fi
password=CF6ECD90B708F354B2CF41AAA833 (*)
directory=/pictures
---clip---

*) the content of the password field changed due to security/privacy
reasons

Workaround:
Do not save FTP connections.

Disclosure Timeline:
02-Dec-2005 - Vulnerability researched and confirmed
03-Dec-2005 - Detailed research, new FTP hosts tested
03-Dec-2005 - Vendor contacted, workaround delivered to the vendor
03-Dec-2005 - Security companies and several CERT units contacted


ADDITIONAL INFORMATION

The information has been provided by <mailto:juha-matti.laurio@xxxxxxxx>
Juha-Matti Laurio.



========================================


This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx


====================
====================

DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.



Relevant Pages

  • Re: Login Box
    ... There could be a number of reasons all related to security. ... What account is your FTP Site using for anonymous users? ...
    (microsoft.public.inetserver.iis.ftp)
  • RE: Mitigate FTP
    ... Yes, using ssh/sftp will help; ... For your customer base, I assume they are mostly Windows users; ... Security may be able to fine tune the threshold accordingly. ... Subject: Mitigate FTP ...
    (Pen-Test)
  • [NT] Windows FTP Client Allows File Transfer Location Tampering (MS05-044)
    ... Get your security news from a reliable source. ... A tampering vulnerability exists in the Windows FTP client. ... * Microsoft Windows Server 2003 for Itanium-based Systems - ...
    (Securiteam)
  • [NEWS] Symantec Enterprise Firewall FTP Bounce Vulnerability (Patch Available)
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Raptor Firewall FTP Bounce Vulnerability. ... PORT command referenced a destination that doesn't ...
    (Securiteam)
  • [UNIX] SafeTP Reveals Internal Server IP Addresses
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Protocol) to connect to their accounts on UNIX or NT/2000 FTP servers. ... check out the "227 Entering Passive Mode ... Timed out waiting for connection from server. ...
    (Securiteam)