Add new attachment

Only authorized users are allowed to upload new attachments.

This page (revision-12) was last changed on 11-Apr-2025 10:01 by Ben Spink

This page was created on 01-Apr-2025 14:11 by Ben Spink

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Difference between version and

At line 1 changed 2 lines
March 21st vulnerability CVE-2025-31161 or the copy cat CVE which triggered the compromising of servers: CVE-2025-0282\\
\\
March 21st vulnerability CVE-2025-31161 or the copy cat CVE which triggered the compromising of servers: CVE-2025-2825\\
----
__A good explanation of the whole exploit in the wild and why it happenned.__\\
[https://www.darkreading.com/vulnerabilities-threats/disclosure-drama-clouds-crushftp-vulnerability-exploitation]\\
----
At line 8 added 2 lines
__If you were not patched by March 28th, and you used the username crushadmin, and your web port was exposed (not the DMZ server), then you were most likely hacked.__\\
\\
At line 8 changed 2 lines
if you see a new crushadmin2 user...
new random GUID looking usernames...
if you see a new crushadmin2, zero, system, long GUID usernames, others users you don't recognize...
At line 18 added one line
Your server was updated to 10.8.4+ and you don't recall doing it...(hackers do this to hide the fact they already compromised you...)
At line 32 added one line
changed service exe files that are doing other activities
At line 34 added one line
hackers install their backdoor...then update your server so you believe you are patched and safe. But if you didn't do the update yourself, and before March 27th, you are not safe and were probably compromised
At line 46 changed one line
How to do an offline update: [OfflineUpdate11] or [OfflineUpdate10]
How to do an offline update: [OfflineUpdate11] or [OfflineUpdate10]\\
Version Date Modified Size Author Changes ... Change note
12 11-Apr-2025 10:01 3.216 kB Ben Spink to previous
11 07-Apr-2025 09:13 3.042 kB Ben Spink to previous | to last
10 04-Apr-2025 15:36 3.042 kB Ben Spink to previous | to last
9 04-Apr-2025 13:44 2.983 kB Ben Spink to previous | to last
8 02-Apr-2025 01:25 2.775 kB Ben Spink to previous | to last
7 02-Apr-2025 01:09 2.639 kB Ben Spink to previous | to last
6 02-Apr-2025 00:52 2.651 kB Ben Spink to previous | to last
5 01-Apr-2025 15:52 2.439 kB Ben Spink to previous | to last
4 01-Apr-2025 14:36 2.402 kB Ben Spink to previous | to last
3 01-Apr-2025 14:25 2.331 kB Ben Spink to previous | to last
2 01-Apr-2025 14:14 1.912 kB Ben Spink to previous | to last
1 01-Apr-2025 14:11 1.818 kB Ben Spink to last
« This page (revision-12) was last changed on 11-Apr-2025 10:01 by Ben Spink
G’day (anonymous guest)
CrushFTP11 | What's New

Referenced by
Update

JSPWiki