Friday, November 15, 2024
Homecyber securityCrushFTP Servers Zero-day Under Active Attack: Update Now

CrushFTP Servers Zero-day Under Active Attack: Update Now

Published on

CrushFTP is a file transfer server that supports secure protocols, offers easier configuration, and offers powerful monitoring tools.

It also provides a web interface that allows users to transfer files using a web browser. 

A critical vulnerability associated with FileSystem escape has been discovered and addressed in the latest version.

- Advertisement - SIEM as a Service

This particular vulnerability allows any user to download system files escaping from the virtual file system present in the CrushFTP application. 

Moreover, there have also been reports indicating the exploitation of this vulnerability in the wild by threat actors.

Free Webinar | Mastering WAAP/WAF ROI Analysis | Book Your Spot

No CVE was assigned to this vulnerability at the time of reporting.

Additionally, customers who use Demilitarized Zones (DMZ) in with their CrushFTP instance are not affected by this vulnerability due to the protocol translation system.

CrushFTP Servers Zero-day

According to the reports shared with Cyber Security News, there have been several exploitation attempts over CrushFTP instances owned by multiple U.S. Entities, which are speculated to be an activity of Politically Motivated Intelligence Gathering.

Exploitation attempts (Source: r/crowdstrike – Reddit)

To provide a brief insight, the CrushFTP application is a bundled stand-alone portal executable (PE) that probably doesn’t have a standard installation location.

The application can run on Windows, macOS and Linux and depend on Java.

To prevent the exploitation of this vulnerability, users of CrushFTP are recommended to upgrade to the latest version, v11.1.0, which has a patch for it.

All versions before CrushFTP v9 are affected.

For more information about the changelogs and other information, the CrushFTP wiki page can be viewed.

How To Update?

To update CrushFTP to the latest version v11.1.0 (for Online users), the following steps can be followed:

  1. Login to the dashboard using your “crushadmin” equivalent user in the WebInterface.
  2. Click on the About tab.
  3. Click Update, Update Now.
  4. Wait roughly 5 minutes for the files to download, unzip, and be copied in place. CrushFTP will auto-restart once done.
  5. Finished.
How to update Online (Source: CrushFTP)

For Offline users, the below steps can be followed

  1. Download CrushFTP11.zip from our download page. (https://www.crushftp.com/early11/CrushFTP11.zip)
  2. Give it the name `CrushFTP10_new.zip` and place it in the CrushFTP main folder. (Same location where you have your prefs.XML file)
  3. See the above normal instructions, as Crush will use your local offline zip file.

Looking to Safeguard Your Company from Advanced Cyber Threats? Deploy TrustNet to Your Radar ASAP.

Eswar
Eswar
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Latest articles

Critical TP-Link DHCP Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious...

Chinese SilkSpecter Hackers Attacking Black Friday Shoppers

SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce...

Cybercriminals Launch SEO Poisoning Attack to Lure Shoppers to Fake Online Stores

The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to...

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Critical TP-Link DHCP Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious...

Critical Laravel Vulnerability CVE-2024-52301 Allows Unauthorized Access

CVE-2024-52301 is a critical vulnerability identified in Laravel, a widely used PHP framework for...

4M+ WordPress Websites to Attacks, Following Plugin Vulnerability

A critical vulnerability has been discovered in the popular "Really Simple Security" WordPress plugin,...