Back Redpacketsecurity CVE Alert: CVE-2015-3306 – n/a – n/a
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.
**Risk verdict:** Urgent: active exploitation is flagged and working exploit material is available; treat as priority 1.
**Why this matters:** An attacker may use the FTP service to access or alter files without valid credentials, potentially exposing sensitive data or changing application content. Where written files can be executed by another service, this may provide a route to code execution and a foothold for further compromise.
**Most likely attack path:** A remotely reachable FTP service is the key precondition; exploitation requires neither user action nor prior privileges. The attacker can act within the FTP service’s security context, and impact may cross into other services or data if that account can write to shared locations.
**Who is most exposed:** Internet-facing ProFTPD deployments are at greatest risk, particularly legacy file-transfer servers and hosts where FTP shares paths with web applications or business data.
Alert on `SITE CPFR` or `SITE CPTO` commands, especially in unusual sequences or from unfamiliar sources.
Review FTP logs for anonymous or unexpected sessions and repeated file-operation failures.
Check web roots, temporary directories and shared storage for recently created or altered files.
Correlate FTP activity with web-server execution, new processes or unexpected outbound connections.
Mitigation and prioritisation
Identify affected hosts and upgrade to a vendor-supported fixed release; verify the module is not enabled where unnecessary.
Restrict FTP access to trusted networks or VPN, and disable the service if it is not required.
Until patched, block the relevant copy commands or disable the module; validate controls against legitimate workflows.
Review file permissions and investigate for compromise before restoring normal service; coordinate changes with file-transfer owners.
A considerable amount of time and effort goes into maintaining this website, creating backend automation and creating new features and content for you to make actionable intelligence decisions. Everyone that supports the site helps enable new functionality.
If you like the site, please support us on Patreon or Buy Me A Coffee using the buttons below.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
