Skip to content

Conversation

@alixthegreat
Copy link

The vulnerability was supposed to give non root access using the proftpd backdoor for 1.3.3. It gave root access every time I tested it, even after checking the permissions and that it was running as the ftp user. Looking online, it mentions that the exploit runs as root, which makes it difficult. The decision was made to remove the non-root scenario and the module entirely, keeping the scenario that grants root access.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant