Title:Suspicious VSFTPD Error Messages Status:test Description:Detects suspicious VSFTPD error messages that indicate a fatal or suspicious error that could be caused by exploiting attempts References: -https://github.com/dagwieers/vsftpd/ Author: Florian Roth (Nextron Systems) Date: 2017-07-05 modified:2021-11-27 Tags:
-'attack.initial-access'
-'attack.t1190'
Logsource:
product: linux
service: vsftpd
Detection: keywords: - 'Connection refused: too many sessions for this address.' - 'Connection refused: tcp_wrappers denial.' - 'Bad HTTP verb.' - 'port and pasv both active' - 'pasv and port both active' - 'Transfer done (but failed to open directory).' - 'Could not set file modification time.' - 'bug: pid active in ptrace_sandbox_free' - 'PTRACE_SETOPTIONS failure' - 'weird status:' - 'couldn't handle sandbox event' - 'syscall * out of bounds' - 'syscall not permitted:' - 'syscall validate failed:' - 'Input line too long.' - 'poor buffer accounting in str_netfd_alloc' - 'vsf_sysutil_read_loop' condition:keywords Falsepositives:
-Unknown Level:medium