Vulnerability Development mailing list archives

Re: linux-ftpd 0.16 is also vulnerable


From: drow () FALSE ORG (Daniel Jacobowitz)
Date: Wed, 28 Jun 2000 14:16:56 -0700


That's wrong.  I don't know if linux-ftpd is vulnerable or not, but I
do know that FTP itself is.  Your client is interpreting the %p.

Note that the X in 0x805F520 is capitalized.  That means that it was
recieved by the server as part of the site command in the first place.

On Tue, Jun 27, 2000 at 11:53:19PM -0300, Paulo Ribeiro wrote:
Hello.

As I can see, linux-ftpd 0.16 is as vulnerable as wu-ftpd-2.6.0.

Demo.:

ftp> SITE %p
500 'SITE 0X805F520': command not understood.
ftp> SITE %s
500 'SITE @:E:': command not understood.
(...)

This e-mail was sent to BUGTRAQ and to the its authors.

Yours,
Paulo Ribeiro.



Dan

/--------------------------------\  /--------------------------------\
|       Daniel Jacobowitz        |__|        SCS Class of 2002       |
|   Debian GNU/Linux Developer    __    Carnegie Mellon University   |
|         dan () debian org         |  |       dmj+ () andrew cmu edu      |
\--------------------------------/  \--------------------------------/


Current thread: