Security Incidents mailing list archives
Re: wuftp exploit
From: drow () FALSE ORG (Daniel Jacobowitz)
Date: Wed, 28 Jun 2000 17:07:09 -0700
On Wed, Jun 28, 2000 at 11:47:38AM -0700, Toby Miller wrote:
All, I have been doing some analysis on the WUFTP exploit, hopefully this will help. Here is a tcpdump of the expoit running on my lab:
<snip>
1) This exploit can be ran against the following OS's: a) Redhat 6.2 b) SuSe 6.3 & 6.4 c) FreeBsd 3.4 & 4.0
And anything else that runs Wu, yes. It just needs simple changes.
2) The ID's(highlighted in green) increment by 1. I ran this exploit 5 times and all five times the ID's incremented by one throughout out the attempt.
That's just a symptom of low network traffic and a lousy random number generator.
3) The two packets with the Psh flag set always contains ten bytes of data. The hex data looks like this: 5553 4552 2066 7470 0d0a
Yes, congratulations. That expands to: USER ftp\r\n You just logged all anonymous ftp connections. There are easier ways. Dan /--------------------------------\ /--------------------------------\ | Daniel Jacobowitz |__| SCS Class of 2002 | | Debian GNU/Linux Developer __ Carnegie Mellon University | | dan () debian org | | dmj+ () andrew cmu edu | \--------------------------------/ \--------------------------------/
Current thread:
- Re: funky syslog entry, (continued)
- Re: funky syslog entry Erich Meier (Jun 28)
- Re: funky syslog entry Sean Michael Whipkey (Jun 28)
- blind forwards Keith McCammon (Jun 28)
- Re: blind forwards Ex Machina (Jun 29)
- Re: blind forwards Brock Norvell (Jun 29)
- Re: blind forwards John Hall (Jun 29)
- Re: blind forwards David Pick (Jun 30)
- Re: funky syslog entry UnixGeek (Jun 29)
- Re: funky syslog entry Chris West (Jun 29)
- wuftp exploit Toby Miller (Jun 28)
- Re: wuftp exploit Daniel Jacobowitz (Jun 28)
- Permissions Derick Schuetz (Jun 27)
- Re: Permissions Valdis Kletnieks (Jun 27)
- Re: Permissions Jon Lewis (Jun 27)
- Probes for MySQL under Linux? Ralf G. R. Bergs (Jun 27)
- Re: Probes for MySQL under Linux? Tabor J. Wells (Jun 27)
- Port scan (106 and 389) Chris Laycock (Jun 28)
- Compromise and Bind Replacement Scott Brown (Jun 28)
- Re: Port scan (106 and 389) Fabio Pietrosanti (Jun 28)
- Re: Probes for MySQL under Linux? Al Huger - Mail Account (Jun 28)
- Was I exploited? Narins, Joshua (Jun 29)