ProFTPD mod_copy Unauthenticated Remote Command Execution (CVE-2015-3306)
Detects exploitation of CVE-2015-3306, an improper access control flaw in the mod_copy module of ProFTPD. The SITE CPFR and SITE CPTO commands are exposed without authentication, allowing a remote attacker to copy arbitrary files on the server. Attackers chain this with the PHP/SSH config to write attacker-controlled data (e.g., a webshell) into a web-accessible directory, achieving unauthenticated remote command execution. This detection looks for anonymous or unauthenticated use of SITE CPFR/CPTO sequences, copies that target web roots or authorized_keys files, and the follow-on execution indicative of a dropped webshell.
Vulnerability Intelligence
KEV — Known ExploitedAffected Software
- Vendor
- ProFTPD
- Product
- ProFTPD
Weakness (CWE)
Timeline
- Disclosed
- April 13, 2015
References & Proof of Concept
- PoChttps://www.exploit-db.com/exploits/37262
- PoChttps://www.exploit-db.com/exploits/36803
- PoChttps://www.exploit-db.com/exploits/49908
- PoChttps://www.exploit-db.com/exploits/36742
- http://www.proftpd.org/
- https://lists.debian.org/debian-security-announce/2015/msg00154.html
- https://lists.opensuse.org/archives/list/[email protected]/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
- https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk
- https://nvd.nist.gov/vuln/detail/CVE-2015-3306
- http://bugs.proftpd.org/show_bug.cgi?id=4169
CVSS
What is CVE-2015-3306 ProFTPD mod_copy Unauthenticated Remote Command Execution (CVE-2015-3306)?
ProFTPD mod_copy Unauthenticated Remote Command Execution (CVE-2015-3306) (CVE-2015-3306) maps to the Initial Access and Execution and Lateral Movement tactics — the adversary is trying to get into your network in MITRE ATT&CK.
This page provides production-ready detection logic for ProFTPD mod_copy Unauthenticated Remote Command Execution (CVE-2015-3306), covering the data sources and telemetry it touches: Syslog, ProFTPD server logs. The queries below are rated critical severity at high confidence, and ship for 7 SIEM platforms — KQL, SPL, Elastic, QRadar, Sumo, YARA-L, LogScale.
MITRE ATT&CK
// ProFTPD mod_copy SITE CPFR/CPTO abuse (CVE-2015-3306)
Syslog
| where Facility in ("daemon", "ftp") or ProcessName has_any ("proftpd", "ftp")
| where SyslogMessage has "SITE" and SyslogMessage has_any ("CPFR", "CPTO")
| extend CopyTarget = extract(@"CPTO\s+(\S+)", 1, SyslogMessage)
| extend CopySource = extract(@"CPFR\s+(\S+)", 1, SyslogMessage)
| where isnotempty(CopyTarget) or SyslogMessage has "CPFR"
| extend SuspiciousTarget = CopyTarget has_any ("/var/www", "/srv/www", "html", ".php", ".jsp", "authorized_keys", "/etc/", "public_html")
| where SuspiciousTarget or SyslogMessage has_cs "USER anonymous"
| project TimeGenerated, Computer, HostIP, Facility, ProcessName, CopySource, CopyTarget, SyslogMessage
| sort by TimeGenerated desc Flags ProFTPD syslog lines containing SITE CPFR/CPTO commands, especially when the copy destination targets web roots, PHP/JSP files, or authorized_keys — the signature of mod_copy exploitation.
Data Sources
Required Tables
False Positives
- Legitimate administrative or backup scripts that invoke SITE CPFR/CPTO for file duplication
- Monitoring tools that exercise FTP SITE commands as health checks
- Authorized file-management automation copying files into web directories
Sigma rule & cross-platform mapping
The detection logic for ProFTPD mod_copy Unauthenticated Remote Command Execution (CVE-2015-3306) (CVE-2015-3306) above is provided in a vendor-neutral
form so you can deploy it on any SIEM. The same logic is shipped here as native
KQL (Microsoft Sentinel / Defender), SPL (Splunk), Elastic (Elastic Security (EQL)), QRadar (IBM QRadar (AQL)), Sumo (Sumo Logic CSE), YARA-L (Google Chronicle / SecOps), LogScale (CrowdStrike LogScale (CQL)) queries. In Sigma terms, this detection targets the
following logsource:
logsource:
product: windows Browse the community-maintained Sigma rules for this technique:
Platform-specific guides for CVE-2015-3306
References (10)
- https://nvd.nist.gov/vuln/detail/CVE-2015-3306
- http://www.proftpd.org/
- https://lists.debian.org/debian-security-announce/2015/msg00154.html
- https://lists.opensuse.org/archives/list/[email protected]/message/WE6YZRG5UVXMGQ7IVDRYBPIWV4M6UUGM/
- https://www.exploit-db.com/exploits/37262
- https://www.exploit-db.com/exploits/36803
- https://www.exploit-db.com/exploits/49908
- https://www.exploit-db.com/exploits/36742
- http://bugs.proftpd.org/show_bug.cgi?id=4169
- https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk
Testing Methodology
Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.
- Test 1ProFTPD mod_copy webshell drop via SITE CPFR/CPTO
Expected signal: ProFTPD SystemLog/TransferLog records containing 'SITE CPFR /tmp/shell.php' and 'SITE CPTO /var/www/html/shell.php'
- Test 2ProFTPD mod_copy SSH key injection
Expected signal: FTP log entries showing SITE CPTO targeting an authorized_keys path
- Test 3ProFTPD SITE CPFR arbitrary file read
Expected signal: FTP log entries showing SITE CPFR /etc/passwd followed by SITE CPTO
Response Playbook
Triage
- Confirm the ProFTPD version on the affected host (banner, `proftpd -v`, package manager) and whether mod_copy is loaded; versions at/before 1.3.5 and 1.3.6rc builds without the fix are vulnerable to CVE-2015-3306.
- Review the FTP session logs around the SITE CPFR/CPTO events to identify the source IP, whether the session was anonymous/unauthenticated, and the exact source and destination file paths that were copied.
- Inspect the copy destination (web root, public_html, or ~/.ssh/authorized_keys) for newly created or modified files — webshells, PHP backdoors, or injected SSH public keys.
- Correlate the FTP copy events with subsequent web-server access logs or shell process execution to determine whether the dropped payload was invoked.
Containment
- Block the attacker source IP(s) at the perimeter firewall and terminate any active FTP sessions from them.
- Disable or unload mod_copy and restrict SITE commands in proftpd.conf (`<Limit SITE_CPFR SITE_CPTO> DenyAll </Limit>`), then restart ProFTPD; patch or upgrade to a fixed ProFTPD release.
- Quarantine or remove any confirmed webshell/backdoor files and revoke injected SSH keys from authorized_keys.
Evidence Collection
- Preserve ProFTPD logs (TransferLog, SystemLog, xferlog) and syslog covering the CPFR/CPTO activity.
- Capture the dropped files (hash, timestamps, content) and the web-server access logs showing any invocation of the payload.
- Collect process, network connection, and auth logs from the host to document post-exploitation activity and attribute the source.
Escalation Criteria
- ! Escalate to incident response if a webshell or backdoor was confirmed written and subsequently executed (confirmed RCE).
- ! Escalate if the host is internet-facing, processes sensitive data, or shows signs of lateral movement or persistence (new accounts, injected SSH keys, cron jobs).
Investigation Guide
Forensic Artifacts
- >
ProFTPD TransferLog/SystemLog entries showing SITE CPFR and SITE CPTO commands - >
Newly created files in web-accessible directories (e.g., /var/www/html/*.php) with FTP-process ownership - >
Modified ~/.ssh/authorized_keys files with unexpected public keys - >
Web-server access-log entries invoking the dropped payload shortly after the FTP copy
Tuning Guidance
If legitimate backup or deployment automation uses SITE CPFR/CPTO, allowlist those specific source IPs or service accounts rather than disabling the rule. Narrow the destination-path regex to your actual web roots to reduce noise, and raise severity when the source session is anonymous/unauthenticated.
Hunting Queries
Surfaces hosts with paired SITE CPFR/CPTO activity over time to spot exploitation attempts even when destination paths are obfuscated.
Syslog | where SyslogMessage has_any ("CPFR","CPTO") | summarize count(), make_set(SyslogMessage) by HostIP, bin(TimeGenerated, 1h) | where count_ > 1 index=* ("CPFR" OR "CPTO") | stats count values(_raw) by host | where count>1 Atomic Red Team Tests
Uses an unauthenticated FTP session to copy a staged PHP webshell into the web root, reproducing CVE-2015-3306 exploitation in a lab.
Command
printf 'USER anonymous\r\nSITE CPFR /tmp/shell.php\r\nSITE CPTO /var/www/html/shell.php\r\nQUIT\r\n' | nc 127.0.0.1 21 Cleanup
rm -f /var/www/html/shell.php Expected Telemetry
ProFTPD SystemLog/TransferLog records containing 'SITE CPFR /tmp/shell.php' and 'SITE CPTO /var/www/html/shell.php'
Expected Detection
KQL/SPL rules fire on the CPTO destination matching /var/www and .php
Copies an attacker public key into a user's authorized_keys via mod_copy to establish persistence.
Command
printf 'SITE CPFR /tmp/attacker.pub\r\nSITE CPTO /home/ftpuser/.ssh/authorized_keys\r\nQUIT\r\n' | nc 127.0.0.1 21 Cleanup
rm -f /home/ftpuser/.ssh/authorized_keys Expected Telemetry
FTP log entries showing SITE CPTO targeting an authorized_keys path
Expected Detection
Rules match on CPTO destination containing 'authorized_keys'
Demonstrates using SITE CPFR to stage a sensitive system file for exfiltration via a subsequent retrieve.
Command
printf 'SITE CPFR /etc/passwd\r\nSITE CPTO /tmp/passwd.copy\r\nQUIT\r\n' | nc 127.0.0.1 21 Cleanup
rm -f /tmp/passwd.copy Expected Telemetry
FTP log entries showing SITE CPFR /etc/passwd followed by SITE CPTO
Expected Detection
Paired CPFR/CPTO hunting query flags the host; CPFR source referencing /etc/ matches the rule