Exploit Code Released for Actively Exploited GoAnywhere MFT Vulnerability
Premium Content
to watch this episode.
Reading Time: 3 Minutes
Actively exploited zero-day vulnerability on GoAnywhere MFT
An actively exploited zero-day vulnerability affecting Internet-exposed GoAnywhere MFT (Managed File Transfer) administrator consoles has been made public by security researcher Florian Hauser of IT security consulting firm Code White.
Well done
GoAnywhere MFT is a web-based tool designed to help organizations securely transfer files and keep audit logs of access. The vulnerability allows for unauthenticated remote code execution on vulnerable GoAnywhere MFT servers.
Although Fortra (the developer behind GoAnywhere MFT) claims that the attack vector requires access to the administrative console of the application, which is usually accessible only from within a private network, Shodan scan results show that almost 1,000 GoAnywhere instances are exposed on the Internet.
Map of vulnerable GoAnywhere MFT servers (Shodan)
See Also: So you want to be a hacker?
Trending:
Are u a security researcher? Or a company that writes articles or write ups about Cyber Security, Offensive Security (related to information security in general) that match with our specific audience and is worth sharing?
If you want to express your idea in an article contact us here for a quote: [email protected]
Source: bleepingcomputer.com

SOCIAL SHARE CARD GENERATOR