Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




bugtraq logo Bugtraq mailing list archives

Re: ftpd: the advisory version
From: kb8rln () PENGUINMASTER COM (Richard Rager)
Date: Tue, 11 Jul 2000 11:47:49 -0600


On Mon, 10 Jul 2000, D. J. Bernstein wrote:

1. Surely there are other people still wondering about proftpd. Can an
attacker take over proftpd 1.2.0pre10? CERT seems to say yes, but the
maintainer says ``relatively minor.'' What's the deal?

   Yes I have had someone get a shell account on my box with proftpd
1.2.0pre10.  I was able to keep him out for a little more with time with
kernel 2.2.16 until the code changed.  This is in the wild!

2. I agree that setproctitle() is rather pointless. My comments were
about all functions with printf()-type format strings. Typical strings
should fail as format strings.

  Yes

  I was running proftpd in stand alone mode.  The proftpd dies in some of
 these attacts.  It was running as user ftp.

Enjoy,

Richard


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]