|
Full Disclosure
mailing list archives
Re: Windows XP SP1 - Microsoft FTP Client
From: Aaron Horst <anthrax101 () gmail com>
Date: Sun, 14 Nov 2004 03:59:44 -0500
Seems to be the classic buffer overflow. It's really easy to write a
little script to take advantage of this due to the -s switch for the
ftp program. I doubt that you could do anything remote with it though,
if you're able to drop a random binary file on the HD and execute a
command, there are better methods of attack. ;) If you're interested
in learning about buffer overflows, figure out how to attack this one.
It's really simple, and as easy as you're going to get.
AnthraX101
On Sat, 13 Nov 2004 19:53:18 -0200, phoenix <phoenix () enforce com br> wrote:
I was testing something on my ftp client, and I got an access violation.
Microsoft Windows XP SP1 (BR) - Microsoft FTP Client
--------------------------------------------------------------------------------
Conectado a localhost.
220 Website FTP Server Ready
Usuário (localhost:(none)): ftp
331 Anonymous login ok, send your complete email address as your password.
Senha:
230 Anonymous access granted, restrictions apply.
ftp> quote dir
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAA
500 DIR not understood
ftp>
..nothing here..
--------------------------------------------------------------------------------
Conectado a localhost.
220 Website FTP Server Ready
Usuário (localhost:(none)): ftp
331 Anonymous login ok, send your complete email address as your password.
Senha:
230 Anonymous access granted, restrictions apply.
ftp> quote dir
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
..CRASH..
--------------------------------------------------------------------------------
Conectado a localhost.
220 Website FTP Server Ready
Usuário (localhost:(none)): ftp
331 Anonymous login ok, send your complete email address as your password.
Senha:
230 Anonymous access granted, restrictions apply.
ftp> quote dir
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
500 DIR not understood
500 DIR not understood
500 DIR not understood
500 DIR not understood
500 DIR not understood
500 DIR not understood
..more and more..
..will it stop?..
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
By Date
By Thread
Current thread:
|