Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Vulnerability Development: Re: twlc advisory: possible overflow in ms ftp client

Re: twlc advisory: possible overflow in ms ftp client

From: <supergate_at_twlc.net>
Date: Thu, 1 Nov 2001 20:29:47 +0100

> > Summary
> > Possible buffer overflow in windows ftp client...
>
> Ok, and what do you gain by this?
> Also see previous threads (yes they are a while ago)
> "ftp.exe buffer overflow" and "FTP.exe risk:low" about
> some other bugs in the ftp client (format string bugs).
>

look at the conclusion of the advisory:

Conclusion
So is prolly possible execute code in the system, and for sure crash the
client (will ever be useful:P?) <- should i make it bold?

i wrote the advisory because its a spreaded program not because it was
dangerous:)

> Anyway, if you like client side bugs you could better search for something
> like server sending "evilstuff" to client which causes (for example) an
overflow.
> In that case you could write a remote exploit... _that_ would be a
security bug

ill make some test and send some string from the SERVER to the client to see
if i can crash it up -if i got the time-

cya
supergate.
Received on Nov 01 2001

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
edgeos