Vulnerability Development mailing list archives

Re: Microsoft FTP service 4.0 ( Overflow? )


From: Steve <steve () SECURESOLUTIONS ORG>
Date: Tue, 20 Feb 2001 23:21:06 -0700

So the connection gets closed, are you able to reconnect?  Do you have
physical access to the box that is running the MS FTP to see if there is a
Dr. Watson or BSOD?  A simple dropped connection might hint of an overflow
but more work is required to properly identify it.

-----Original Message-----
From: VULN-DEV List [mailto:VULN-DEV () SECURITYFOCUS COM]On Behalf Of
Guile cool
Sent: Monday, March 19, 2001 3:14 AM
To: VULN-DEV () SECURITYFOCUS COM
Subject: Microsoft FTP service 4.0 ( Overflow? )


I just did :
telnet www.sux.com 21
CONNECTED
Microsoft FTP service 4.0
%s%s%s%S%s%s%s%s%s%s%s%s%s%s%s%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%
S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%
s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%
s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s
%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s
%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s
%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s
%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%
s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%
s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%
s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%
%s%s%s%S%s%s%s%s%s%s%s%s%s%s%
Connection closed by foreign host.
What do u think about it?
Bye :>
_________________________________________________________________________
Get Your Private, Free E-mail from MSN Hotmail at http://www.hotmail.com.


Current thread: