Full Disclosure mailing list archives
Re: PlatinumFTP 1.0.18 remote DoS
From: "Gary H. Jones II" <gary () pointblanksecurity com>
Date: Sat, 12 Mar 2005 14:23:04 -0500
That software uses an FTP server ActiveX control made by Mabry Software. Any ftp server that uses this activex control is vulnerable. The ActiveX control is the cause of these bugs, not the PlatinumFTP software itself, when I took a look at the software, I noticed it was written in VB5, finding a format string in a program written in VB would be a *very* rare find, so I figured there would be a 3rd party control within the app that was written in C++. I ran it through a debugger, passed a few %s's and watched it crash. The title of the error message is "Mabry Socket Window: PlatinumFTPserverEngine.exe - Application Error", this is what lead to the discovery of the real issue. I downloaded the latest sample/demo of this ActiveX, and it is still vulnerable when you run VBSampleOCX.exe. Available here http://www.mabry.com/ftpserv/index.htm. There has been an advisory released already for this ActiveX control. http://secunia.com/advisories/10608/ -Gary ----- Original Message ----- From: "ports" <ml () portsonline net> To: "Gary H. Jones II" <gary () pointblanksecurity com> Cc: <full-disclosure () lists grok org uk> Sent: Saturday, March 12, 2005 1:13 PM Subject: Re: [Full-disclosure] PlatinumFTP 1.0.18 remote DoS
Gary H. Jones II wrote:Reported in 2003 already... classic format string vulnerabilities http://www.derkeiler.com/Mailing-Lists/Securiteam/2003-12/0080.htmlYes, found that one as well. But since I found some additional Strings I thought it might be interesting to post them :)-garyports
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://www.secunia.com/
Current thread:
- PlatinumFTP 1.0.18 remote DoS ports (Mar 12)
- Re: PlatinumFTP 1.0.18 remote DoS Gary H. Jones II (Mar 12)
- Re: PlatinumFTP 1.0.18 remote DoS ports (Mar 12)
- Re: PlatinumFTP 1.0.18 remote DoS Gary H. Jones II (Mar 12)
- Re: PlatinumFTP 1.0.18 remote DoS ports (Mar 12)
- Re: PlatinumFTP 1.0.18 remote DoS ports (Mar 12)
- Re: PlatinumFTP 1.0.18 remote DoS Gary H. Jones II (Mar 12)