Vulnerability Development mailing list archives
Re: (pointless?) overflow in tftp.exe (Was: Re: twlc advisory: possible overflow in ms ftp client)
From: supergate () twlc net
Date: Fri, 2 Nov 2001 15:33:24 +0100
----- Original Message ----- From: <foob () return0 net> To: <supergate () twlc net> Cc: <vuln-dev () securityfocus com> Sent: Friday, November 02, 2001 11:36 AM Subject: (pointless?) overflow in tftp.exe (Was: Re: twlc advisory: possible overflow in ms ftp client)
(excuse the formatting, damn cmd.exe cut n paste sucks). "The instruction at "0x........" referenced memory at "0x41414141". Maybe a heap overflow. Probably usable to run code. Pointless-factor-10. As far as i can tell, the remote server doesnt need to exist - it crashes before the network is used.
i made some test sending string from the server to the client and nothing.... so i guess its more useless than before
One possible non-pointless use of such client overflows could be if you can remotely run commands on a machine, say through IIS, but not upload code. You could use this with some payload to execute arbitrary code. Probably.
yes this is obiuvsly possible supergate.
Current thread:
- twlc advisory: possible overflow in ms ftp client supergate (Nov 01)
- Re: twlc advisory: possible overflow in ms ftp client Syzop (Nov 01)
- Re: twlc advisory: possible overflow in ms ftp client supergate (Nov 01)
- <Possible follow-ups>
- Re: twlc advisory: possible overflow in ms ftp client supergate (Nov 01)
- (pointless?) overflow in tftp.exe (Was: Re: twlc advisory: possible overflow in ms ftp client) foob (Nov 02)
- Re: (pointless?) overflow in tftp.exe (Was: Re: twlc advisory: possible overflow in ms ftp client) supergate (Nov 02)
- Re: (pointless?) overflow in tftp.exe (Was: Re: twlc advisory: possible overflow in ms ftp client) Lincoln Yeoh (Nov 03)
- Re: (pointless?) overflow in tftp.exe (Was: Re: twlc advisory: possible overflow in ms ftp client) Robert Freeman (Nov 04)
- Shutting down windows NT remotely (without winnt toolkit)? Lincoln Yeoh (Nov 04)
- Re: Shutting down windows NT remotely (without winnt toolkit)? Robert Freeman (Nov 05)
- Re: Shutting down windows NT remotely (without winnt toolkit)? Lincoln Yeoh (Nov 08)
- Re: Shutting down windows NT remotely (without winnt toolkit)? Robert Freeman (Nov 08)
- Re: Shutting down windows NT remotely (without winnt toolkit)? Marshal (Nov 09)
- (pointless?) overflow in tftp.exe (Was: Re: twlc advisory: possible overflow in ms ftp client) foob (Nov 02)
- Re: twlc advisory: possible overflow in ms ftp client Syzop (Nov 01)