Add new attachment

Only authorized users are allowed to upload new attachments.

List of attachments

Kind Attachment Name Size Version Date Modified Author Change note
minor_update.jpg 356.6 kB 1 05-Dec-2023 05:32 Ada Csaba

This page (revision-35) was last changed on 01-Aug-2024 11:05 by Sandor

This page was created on 05-Dec-2023 05:32 by Ben Spink

Only authorized users are allowed to rename pages.

Only authorized users are allowed to delete pages.

Difference between version and

At line 1 changed 2 lines
__April 19th, 2024\\
CrushFTP v11 versions below 11.1 have a vulnerability where users can escape their VFS and download system files. This has been patched in v11.1.0. Customers using a [DMZ] in front of their main CrushFTP instance are protected with its protocol translation system it utilizes. (CREDIT:Simon Garrelou, of Airbus CERT)__\\
__April 19th, 2024 - CVE-2024-4040\\
CrushFTP v11 versions below 11.1 have a vulnerability where users can escape their VFS and download system files. This has been patched in v11.1.0. Customers using a [DMZ] in front of their main CrushFTP instance are partially protected with its protocol translation system it utilizes. A DMZ however does not fully protect you and you must update immediately. (CREDIT:Simon Garrelou, of Airbus CERT)__\\
At line 7 changed 2 lines
•Can you tell me how I can check if I have been exploited? Not really..the nature of this was common words that could be in your log already. So there is no silver bullet search term to check for.\\
•If I have a DMZ am I really safe? Sort of...the attacker could steal files from the DMZ, but the DMZ shouldn't have users, no private keys, no data files, etc...still some OS files, but there shouldn't be anything of real interest.\\
•Can you tell me how I can check if I have been exploited? Not really..the nature of this was common words that could be in your log already. So there is no silver bullet search term to check for. Looking for "<INCLUDE" is an indicator.\\
•If I have a DMZ am I safe? NO! As of April 22, we have changed our opinion on this. A DMZ does not fully protect you.\\
At line 25 changed one line
2.) Give it the specific name `` and place this in the CrushFTP main folder. (Same location where you have your prefs.XML file)\\
2.) Give it the specific name `` and place this in the CrushFTP main folder. (Same location where you have your prefs.XML file)\\
Version Date Modified Size Author Changes ... Change note
35 01-Aug-2024 11:05 2.982 kB Sandor to previous
34 22-Apr-2024 15:52 2.982 kB Ben Spink to previous | to last
33 22-Apr-2024 15:51 3.006 kB Ben Spink to previous | to last
32 22-Apr-2024 12:39 2.99 kB Ben Spink to previous | to last
31 22-Apr-2024 12:25 3.028 kB Ben Spink to previous | to last
30 22-Apr-2024 12:23 2.964 kB Ben Spink to previous | to last
29 19-Apr-2024 12:37 2.16 kB Ada Csaba to previous | to last
28 19-Apr-2024 12:36 2.157 kB Ada Csaba to previous | to last
27 19-Apr-2024 12:36 2.153 kB Ada Csaba to previous | to last
26 19-Apr-2024 12:34 2.604 kB Ada Csaba to previous | to last
25 19-Apr-2024 05:27 0.521 kB Ben Spink to previous | to last
24 19-Apr-2024 04:58 0.48 kB Ben Spink to previous | to last
23 28-Feb-2024 03:11 0.132 kB Ben Spink to previous | to last
22 28-Feb-2024 03:10 0.104 kB Ben Spink to previous | to last
21 27-Feb-2024 03:43 4.237 kB Ben Spink to previous | to last
« This page (revision-35) was last changed on 01-Aug-2024 11:05 by Sandor
G’day (anonymous guest)
CrushFTP11 | What's New

Referenced by