nanog mailing list archives
Re: FTP exploit?
From: "ken harris." <ken () boii com>
Date: Mon, 19 Mar 2001 19:17:32 -0500
probably due to the increasingly long thread on vulnerabilities in ftpds that is going on over in BUGTRAQ. Nothing too new, but every time a new 'sploit' is released there, every kiddie on the block just has to try it.
to be a bit more specific. the exploit/bug comes from a problem with globbing. (ie: ls */../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*) affected ftp daemons are the majority of them (proftpd etc) except ncftpd and glftpd from what i've seen. it was another one of those 'i'm so elite i'm going to notify the vendors 30 minutes before posting to bugtraq' so right now vendors are working on latest versions. cheers, -ken harris.
Current thread:
- FTP exploit? Clayton Fiske (Mar 19)
- Re: FTP exploit? Ben Beuchler (Mar 19)
- Re: FTP exploit? Scott Francis (Mar 19)
- Re: FTP exploit? ken harris. (Mar 19)
- Re: FTP exploit? Daniel Roesen (Mar 20)
- Re: FTP exploit? ken harris. (Mar 19)
- <Possible follow-ups>
- Re: FTP exploit? Spencer . Wood (Mar 19)