Back to Intelligence

CVE-2015-3306 Exploited in the Wild: ProFTPD mod_copy SITE CPFR/CPTO Added to CISA KEV — Detection and Remediation Guide

SA
Security Arsenal Team
October 9, 2026
12 min read

On October 8, 2026, CISA added CVE-2015-3306 — an improper access control vulnerability in ProFTPD's mod_copy module — to the Known Exploited Vulnerabilities (KEV) catalog. That addition is not administrative housekeeping. A CVE only lands in the KEV when CISA has reliable evidence of active exploitation in the wild, right now. Despite this flaw being disclosed over a decade ago, threat actors are still finding — and compromising — internet-exposed ProFTPD servers that have never been patched or hardened against it.

If you operate any Linux or Unix infrastructure that exposes FTP services, this is an action-required event. The vulnerability allows unauthenticated remote attackers to read and write arbitrary files on the target host using the SITE CPFR and SITE CPTO commands. In practical terms, exploitation typically means an attacker copies a PHP web shell (or other executable payload) into a web-accessible directory and achieves remote code execution under the context of the FTP or web server process. CISA's required action is explicit: apply vendor mitigations in accordance with BOD 26-04 guidance, or discontinue use of the product if mitigations are unavailable.

The uncomfortable lesson here is one I deliver to clients constantly: attacker tooling does not care how old a CVE is. Exploit kits and initial access brokers recycle reliable primitives indefinitely, and a file-copy-to-RCE primitive with no authentication requirement is exactly the kind of bug that never stops paying out. The 2026 KEV addition proves it.

Technical Analysis

Affected Products and Versions

  • Product: ProFTPD, specifically the mod_copy module
  • Affected versions: ProFTPD 1.3.5 and earlier builds shipping mod_copy enabled (the module was enabled by default in 1.3.5). Vendor-fixed releases are 1.3.5a and 1.3.6rc1 and later.
  • Platforms: Any Linux/Unix distribution that shipped vulnerable ProFTPD packages — Debian, Ubuntu, CentOS/RHEL, and numerous embedded appliances and NAS devices that bundle ProFTPD for file services. Distribution backports mean you must verify behavior, not just the package version string.
  • Exposure requirement: TCP port 21 (or the configured FTP port) reachable by the attacker. No valid credentials are required if mod_copy is active, because the SITE CPFR/SITE CPTO command handlers fail to enforce authentication/authorization before operating.

Vulnerability Mechanics (Defender's View)

CVE-2015-3306 is classified as improper access control (CWE-284). NVD assigned it a CVSS v2 score of 10.0 (AV:N/AC:L/Au:N/C:C/I:C/A:C) — the maximum — reflecting unauthenticated network exploitation with full confidentiality, integrity, and availability impact.

The mod_copy module implements the SITE CPFR (copy from) and SITE CPTO (copy to) FTP commands, intended to let authenticated users duplicate files within their authorized directory scope. The flaw: the command handlers execute the copy operation without verifying that the session is authenticated or that the requesting user has rights to the source and destination paths. The attack chain defenders should model:

  1. Attacker connects to the FTP service and issues SITE CPFR /path/to/source followed by SITE CPTO /path/to/destination — pre-authentication.
  2. The daemon performs the file copy with the privileges of the ProFTPD process.
  3. For arbitrary read: the attacker copies sensitive files (e.g., /etc/passwd, application configs, private keys) into an FTP-accessible or web-accessible directory and retrieves them.
  4. For arbitrary write / RCE: the attacker first uploads a payload via FTP (or sources a writable file on disk), then copies it into a web root — e.g., SITE CPTO /var/www/html/shell.php — and requests it over HTTP. Result: code execution as the web or FTP service account.

Exploitation Status

  • CISA KEV: Added 2026-10-08 — confirmed active exploitation.
  • Public exploit code: Metasploit module (exploit/unix/ftp/proftpd_modcopy_exec) and multiple PoCs have existed for years, meaning exploitation is fully automated and trivially repeatable.
  • Current campaign profile: The 2026 KEV addition indicates ongoing scanning and compromise of legacy FTP services — consistent with botnet operators and initial access brokers harvesting low-hanging internet-facing infrastructure for webshell deployment, cryptomining, and staging.

Required Federal Action

Per the KEV entry and BOD 26-04 (Prioritizing Security Updates Based on Risk), federal civilian executive branch agencies must remediate by the due date listed in the KEV catalog (typically ~3 weeks from addition — verify the exact deadline in the catalog entry), and all organizations should evaluate each asset's internet exposure. CISA also references its Forensics Triage Requirements — if you find a vulnerable, internet-exposed instance, assume compromise and preserve evidence before remediation.

Detection & Response

This is a technical threat with active exploitation. The following detections target the observable behaviors of mod_copy abuse: anomalous SITE CPFR/CPTO commands in FTP logs, unexpected file creation in web roots, and ProFTPD-adjacent webshell execution.

Sigma Rules

YAML
---
title: ProFTPD SITE CPFR CPTO Command Abuse (CVE-2015-3306)
id: 3f8a1c24-9b6d-4e72-a5c1-7d2e8f4b9a06
status: experimental
description: Detects SITE CPFR or SITE CPTO commands in ProFTPD logs, indicative of mod_copy abuse for arbitrary file read/write (CVE-2015-3306). Any occurrence on an internet-facing server warrants immediate investigation.
references:
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2015-3306
  - https://nvd.nist.gov/vuln/detail/CVE-2015-3306
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.initial_access
  - attack.t1190
logsource:
  product: linux
  service: ftp
detection:
  selection:
    - 'SITE CPFR'
    - 'SITE CPTO'
    - 'site cpfr'
    - 'site cpto'
falsepositives:
  - Rare; legitimate use of mod_copy SITE commands is uncommon in production. Baseline any sanctioned file-management workflows and alert on all other hits.
level: high
---
title: Webshell or Executable File Created in Web Root via FTP Context
id: 6c2d9e17-4a8b-4f35-b1d9-2e7c5a3f8d41
status: experimental
description: Detects creation of script/executable files in common web server document roots, consistent with CVE-2015-3306 exploitation copying a payload into a web-accessible path for remote code execution.
references:
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2015-3306
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: file_event
  product: linux
detection:
  selection_path:
    TargetFilename|contains:
      - '/var/www/html/'
      - '/var/www/'
      - '/srv/www/'
      - '/usr/share/nginx/html/'
      - '/htdocs/'
  selection_ext:
    TargetFilename|endswith:
      - '.php'
      - '.php5'
      - '.phtml'
      - '.jsp'
      - '.jspx'
      - '.asp'
      - '.aspx'
      - '.cgi'
      - '.pl'
      - '.py'
      - '.sh'
  condition: all of selection_*
falsepositives:
  - Legitimate deployments by developers or CI/CD pipelines. Correlate the creating process and deployment windows; treat out-of-band creations by www-data, ftp, or nobody as critical.
level: high
---
title: Web Server Process Spawning Shell or System Utilities
id: 9e4b7f03-1d6a-4c82-b8e5-5f3a9d2c7b18
status: experimental
description: Detects web server or FTP service processes spawning interactive shells or system utilities, a common post-exploitation behavior after webshell deployment via CVE-2015-3306.
references:
  - https://attack.mitre.org/techniques/T1059/004/
  - https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2015-3306
author: Security Arsenal
date: 2026/10/09
tags:
  - attack.execution
  - attack.t1059.004
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/apache2'
      - '/httpd'
      - '/nginx'
      - '/php-fpm'
      - '/proftpd'
  selection_child:
    Image|endswith:
      - '/bash'
      - '/sh'
      - '/dash'
      - '/zsh'
      - '/python'
      - '/python3'
      - '/perl'
      - '/nc'
      - '/ncat'
      - '/netcat'
      - '/curl'
      - '/wget'
  condition: all of selection_*
falsepositives:
  - Some legitimate PHP applications shell out to system tools (image processing, backups). Investigate parent/child lineage and command lines; unexplained shell spawns from web processes are almost always malicious.
level: high

KQL (Microsoft Sentinel / Defender)

For environments ingesting Linux syslog and ProFTPD logs into Sentinel via the Syslog/CEF connectors, hunt for the SITE CPFR/SITE CPTO commands and webshell-style file creation:

KQL — Microsoft Sentinel / Defender
// Hunt 1: ProFTPD mod_copy SITE CPFR/CPTO abuse in syslog/CEF ingestion
union isfuzzy=true Syslog, CommonSecurityLog
| where TimeGenerated > ago(14d)
| where SyslogMessage has_any ("SITE CPFR", "SITE CPTO", "site cpfr", "site cpto")
   or Message has_any ("SITE CPFR", "SITE CPTO")
| extend Command = coalesce(SyslogMessage, Message)
| summarize FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated), Hits = count()
  by Computer, ProcessName, SourceIP = coalesce(SourceIP, "unknown"), Command
| order by LastSeen desc
;
// Hunt 2: Script files written to web roots (Linux auditd/sysmon-for-linux file events via Syslog)
Syslog
| where TimeGenerated > ago(14d)
| where SyslogMessage has_any ("/var/www/html/", "/var/www/", "/srv/www/", "/usr/share/nginx/html/")
| where SyslogMessage has_any (".php", ".phtml", ".jsp", ".cgi", ".pl", ".sh")
| where SyslogMessage has_any ("open", "creat", "write", "rename")
| project TimeGenerated, Computer, ProcessName, SyslogMessage
| order by TimeGenerated desc
;
// Hunt 3 (Defender for Endpoint onboarded Linux): web/ftp processes spawning shells
DeviceProcessEvents
| where TimeGenerated > ago(14d)
| where InitiatingProcessFileName has_any ("apache2", "httpd", "nginx", "php-fpm", "proftpd")
| where FileName has_any ("bash", "sh", "dash", "python", "python3", "perl", "nc", "ncat", "curl", "wget")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine,
          FileName, ProcessCommandLine, AccountName
| order by TimeGenerated desc

Velociraptor VQL

For live forensic triage on suspected-compromised hosts, pull recently modified executable/script files in web roots and correlate with listening FTP services:

VQL — Velociraptor
-- Hunt: recent script files in web roots (potential webshells from CVE-2015-3306)
SELECT FullPath, Size, Mtime, Ctime
FROM glob(globs=['/var/www/**/*.php', '/var/www/**/*.phtml', '/var/www/**/*.sh',
                 '/var/www/**/*.cgi', '/var/www/**/*.pl', '/srv/www/**/*.php',
                 '/usr/share/nginx/html/**/*.php'])
WHERE Mtime > now() - (14 * 24 * 3600)
ORDER BY Mtime DESC
VQL — Velociraptor
-- Hunt: confirm ProFTPD exposure and process context
SELECT Pid, Name, CommandLine, Username, Exe
FROM pslist()
WHERE Name =~ 'proftpd' OR CommandLine =~ 'proftpd'
VQL — Velociraptor
-- Hunt: FTP listeners exposed on the host
SELECT Pid, Name, LocalAddress, LocalPort, RemoteAddress, RemotePort, Status
FROM netstat()
WHERE LocalPort = 21 AND Status =~ 'LISTEN'

Remediation & Verification Script

Use this Bash script to inventory exposure, verify whether mod_copy is loaded, test for the vulnerable behavior, and apply the safest available mitigation. Run as root on any host where ProFTPD is installed:

Bash / Shell
#!/bin/bash
# CVE-2015-3306 ProFTPD mod_copy - inventory, verify, mitigate
set -u

echo "=== [1] ProFTPD installation and version ==="
if command -v proftpd >/dev/null 2>&1; then
    proftpd -v 2>/dev/null || /usr/sbin/proftpd -v
else
    echo "proftpd not installed on this host. Exiting."
    exit 0
fi

echo "=== [2] Check if mod_copy is loaded ==="
MODCOPY_LOADED=0
if proftpd -l 2>/dev/null | grep -q mod_copy; then
    echo "[!] mod_copy is COMPILED IN"
    MODCOPY_LOADED=1
fi
for conf in /etc/proftpd/proftpd.conf /etc/proftpd.conf /etc/proftpd/modules.conf; do
    [ -f "$conf" ] && grep -i 'LoadModule.*mod_copy' "$conf" && MODCOPY_LOADED=1
done
[ "$MODCOPY_LOADED" -eq 0 ] && echo "[+] mod_copy does not appear to be loaded (still verify at runtime)"

echo "=== [3] Runtime test: unauthenticated SITE CPFR (expected: rejected) ==="
FTP_PORT=$(grep -hE '^\s*Port' /etc/proftpd/proftpd.conf /etc/proftpd.conf 2>/dev/null | awk '{print $2}' | head -1)
FTP_PORT=${FTP_PORT:-21}
RESPONSE=$(printf 'SITE CPFR /etc/passwd\r\nSITE CPTO /tmp/.cve20153306_test\r\nQUIT\r\n' | timeout 5 nc 127.0.0.1 "$FTP_PORT" 2>/dev/null)
echo "$RESPONSE"
if echo "$RESPONSE" | grep -qi '250'; then
    echo "[CRITICAL] Host responds 250 to unauthenticated SITE CPFR/CPTO - VULNERABLE"
else
    echo "[+] Commands rejected (530/500) - access control enforced"
fi
rm -f /tmp/.cve20153306_test

echo "=== [4] Check internet exposure of FTP port ==="
ss -tlnp 2>/dev/null | grep -E ":${FTP_PORT}\s" || netstat -tlnp 2>/dev/null | grep ":${FTP_PORT} "

echo "=== [5] Mitigation options ==="
echo "Option A (PREFERRED): Upgrade ProFTPD to 1.3.5a/1.3.6rc1 or later via your package manager:"
echo "    Debian/Ubuntu: apt-get update && apt-get install --only-upgrade proftpd-basic proftpd"
echo "    RHEL/CentOS:   yum update proftpd   (or dnf update proftpd)"
echo "Option B: Disable mod_copy - remove/comment 'LoadModule mod_copy.c' from modules.conf"
echo "          and any <IfModule mod_copy.c> blocks, then: systemctl restart proftpd"
echo "Option C: If the service is not required - STOP AND REMOVE IT per CISA KEV guidance:"
echo "    systemctl stop proftpd && systemctl disable proftpd"
echo "    apt-get remove --purge proftpd-basic   # or: yum remove proftpd"

echo "=== [6] Post-exploitation sweep: recent scripts in web roots ==="
find /var/www /srv/www /usr/share/nginx/html -type f \( -name '*.php' -o -name '*.phtml' -o -name '*.sh' -o -name '*.cgi' -o -name '*.pl' \) -mtime -14 -ls 2>/dev/null

echo "=== [7] Historical SITE CPFR/CPTO hits in logs ==="
grep -ihE 'SITE (CPFR|CPTO)' /var/log/proftpd/*.log /var/log/xferlog /var/log/syslog* 2>/dev/null | tail -50

Remediation

Given confirmed active exploitation, treat this as an emergency change, not a routine patch cycle:

  1. Inventory and exposure assessment (today). Identify every host running ProFTPD — including appliances, NAS devices, and container images that bundle it. Determine which instances are internet-reachable. CISA's KEV directive explicitly assigns stakeholders responsibility for evaluating each asset's internet exposure. External attack surface scanning (or a simple nmap -p 21 sweep against your public ranges) will find what your CMDB missed.

  2. Patch (preferred). Upgrade to ProFTPD 1.3.5a or 1.3.6rc1 or later (the vendor-fixed releases). Note that most distributions backported the fix, so validate with the runtime test in the script above rather than trusting the version string alone. Vendor reference: the ProFTPD project (http://www.proftpd.org/) and the original defect record; CISA KEV entry: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2015-3306

  3. Workaround if patching is blocked. Disable mod_copy: remove or comment the LoadModule mod_copy.c directive (typically in /etc/proftpd/modules.conf) and any <IfModule mod_copy.c> configuration blocks, then restart the service. This eliminates the vulnerable command handlers entirely. Additionally restrict FTP to known source IPs via firewall policy and enforce TLS with strong authentication — but understand that network filtering is a compensating control, not a fix.

  4. Discontinue use where mitigations are unavailable. CISA's required action is unambiguous: if you cannot patch or disable the module — common on end-of-life appliances — take the service offline or replace the product. Legacy FTP has no defensible place on the modern internet; migrate file transfer workloads to SFTP/SSH or managed alternatives.

  5. Assume breach on exposed, vulnerable instances. Any internet-facing host that was running a vulnerable mod_copy configuration should be treated as potentially compromised. Follow CISA's Forensics Triage Requirements: preserve logs (/var/log/proftpd/, xferlog, syslog, web server access logs) before remediation, hunt for webshells in document roots using the detections above, review outbound connections from the FTP/web service accounts, and rotate any credentials that could have been read via the arbitrary-file-read primitive (system accounts, application configs, keys).

  6. Meet the KEV deadline. Federal agencies: remediate by the due date in the KEV catalog entry under BOD 26-04. Private-sector organizations should adopt the same timeline as an internal SLA — the exploitation is not theoretical, and scanning for port 21 with this exploit is fully automated.

  7. Verify remediation. Re-run the runtime SITE CPFR/SITE CPTO test after patching or disabling the module and confirm the commands are rejected pre-authentication. Add the host to continuous vulnerability scanning with a KEV-priority policy so regressions (e.g., a container image reintroducing the old package) are caught.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.