Full Disclosure mailing list archives

Re: Windows XP SP1 - Microsoft FTP Client


From: Aaron Horst <anthrax101 () gmail com>
Date: Sun, 14 Nov 2004 03:59:44 -0500

Seems to be the classic buffer overflow. It's really easy to write a
little script to take advantage of this due to the -s switch for the
ftp program. I doubt that you could do anything remote with it though,
if you're able to drop a random binary file on the HD and execute a
command, there are better methods of attack. ;) If you're interested
in learning about buffer overflows, figure out how to attack this one.
It's really simple, and as easy as you're going to get.

AnthraX101


On Sat, 13 Nov 2004 19:53:18 -0200, phoenix <phoenix () enforce com br> wrote:
I was testing something on my ftp client, and I got an access violation.

Microsoft Windows XP SP1 (BR) - Microsoft FTP Client

--------------------------------------------------------------------------------
Conectado a localhost.
220 Website FTP Server Ready
Usuário (localhost:(none)): ftp
331 Anonymous login ok, send your complete email address as your password.
Senha:
230 Anonymous access granted, restrictions apply.
ftp> quote dir
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAA
500 DIR not understood
ftp>
..nothing here..

--------------------------------------------------------------------------------
Conectado a localhost.
220 Website FTP Server Ready
Usuário (localhost:(none)): ftp
331 Anonymous login ok, send your complete email address as your password.
Senha:
230 Anonymous access granted, restrictions apply.
ftp> quote dir
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
..CRASH..

--------------------------------------------------------------------------------
Conectado a localhost.
220 Website FTP Server Ready
Usuário (localhost:(none)): ftp
331 Anonymous login ok, send your complete email address as your password.
Senha:
230 Anonymous access granted, restrictions apply.
ftp> quote dir
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
500 DIR not understood
500 DIR not understood
500 DIR not understood
500 DIR not understood
500 DIR not understood
500 DIR not understood
..more and more..
..will it stop?..

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: