Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:




fulldisclosure logo Full Disclosure mailing list archives

Re: XBOX EvolutionX ftp 'cd' command and telnet 'dir' buffer overflow
From: Stefan Esser <s.esser () e-matters de>
Date: Tue, 10 Feb 2004 09:33:43 +0100

Morning

XBOX EvolutionX ftp 'cd' command and telnet 'dir' buffer overflow

beside the fact that EvolutionX is illegal software, because it is
compiled against the leaked Microsoft XBOX XDK, your indepth analysis
lacks the most funny part:

You can crash evolutionX by just connecting to the ftp server and
supplying a long username:password combination.

Ohh and unlike your crashes this one is preauth.

Stefan Esser


-- 

--------------------------------------------------------------------------
 Stefan Esser                                        s.esser () e-matters de
 e-matters Security                         http://security.e-matters.de/

 GPG-Key                gpg --keyserver pgp.mit.edu --recv-key 0xCF6CAE69 
 Key fingerprint       B418 B290 ACC0 C8E5 8292  8B72 D6B0 7704 CF6C AE69
--------------------------------------------------------------------------
 Did I help you? Consider a gift:            http://wishlist.suspekt.org/
--------------------------------------------------------------------------

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]