CVE-2000-1033
Serv-U FTP Server - Unauthenticated Password Guessing Bypass via Anti-Hammering Feature
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2000-1033. PoCs published by Craig.
AI-analyzed exploit summary This Java-based exploit bypasses the anti-brute-force mechanism in FTP Serv-U by maintaining an authenticated session (anonymous or valid) while brute-forcing other credentials. It leverages the server's failure to disconnect active sessions after repeated failed login attempts.
Description
Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (possibly anonymous) and then attempting to guess the passwords of other users.
Exploits (1)
This Java-based exploit bypasses the anti-brute-force mechanism in FTP Serv-U by maintaining an authenticated session (anonymous or valid) while brute-forcing other credentials. It leverages the server's failure to disconnect active sessions after repeated failed login attempts.