what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

wftpd.txt

wftpd.txt
Posted Nov 2, 2005
Authored by unl0ck | Site exploiterz.org

Windows FTP server unicode buffer overflow.

tags | overflow
systems | windows
SHA-256 | 5a5f9c6f43eb5ff0bc65caa154260e8179fea3c69dfb2478d00272f4613e438c

wftpd.txt

Change Mirror Download
                        -= Unl0ck Team Security Advisory =-

____ ___ __ _______ __ ___________
| | \____ | | \ _ \ ____ | | __ \__ ___/___ _____ _____
| | / \| | / /_\ \_ / ___\| |/ / | |_/ __ \\__ \ / \
| | / | \ |_\ \_/ \ \___ | < | |\ ___/ / __ \| Y Y \
|______/|___| /____/\_____ /\_____ >__|_ \ |____| \___ >____ /__|_| /
\/ \/ \/ \/ \/ \/ \/
... the best way of protection is attack

http://unl0ck.void.ru

Advisory : #11 by unl0ck team
Product : Win Ftp Server (latest version)
Vendor : http://www.wftpserver.com/
Date : 11.02.2005
Impact : unicode buffer overflow
Advisory URL : http://unl0ck.void.ru/papers/adv/wftpd.txt

-=[ Overview

WinFTP Server is a multithreaded FTP server for Windows 98/NT/XP.
It comes with an easy to use interface and can be accessed from
the system tray. The server handles all basic FTP commands and
offers easy account management and support for virtual directories.
It tries to bring all the user's requested features together. It is
the most simple and powerful FTP server to install and manage.

]=-

-=[ Vulnerability

Unicode Buffer Overflow Vulnerability exist in many commands of this win32 server.
For example in USER, PASS, CWD, MKD etc... By sending very long command, server will crash.
If server run in debugger (i.e. OllyDbg) you will see that EIP register will overwrite to
0x00610061, this picture say to us, that this is unicode buffer overflow.
Some commands using SEH technique.
PoC exploit you can find in our site. In releases section.

]=-


-=[ Credits

The bug was founded by Dark Eagle
Unl0ck Team [http://unl0ck.void.ru]

]=-

-=[ Greetz

All greetz go out to: nekd0, antiq, choix, coki, tal0n, crash-x, setnf, 0xdeadbabe, gst etc...

]=-
Login or Register to add favorites

File Archive:

June 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jun 1st
    0 Files
  • 2
    Jun 2nd
    0 Files
  • 3
    Jun 3rd
    18 Files
  • 4
    Jun 4th
    21 Files
  • 5
    Jun 5th
    0 Files
  • 6
    Jun 6th
    57 Files
  • 7
    Jun 7th
    6 Files
  • 8
    Jun 8th
    0 Files
  • 9
    Jun 9th
    0 Files
  • 10
    Jun 10th
    12 Files
  • 11
    Jun 11th
    27 Files
  • 12
    Jun 12th
    38 Files
  • 13
    Jun 13th
    0 Files
  • 14
    Jun 14th
    0 Files
  • 15
    Jun 15th
    0 Files
  • 16
    Jun 16th
    0 Files
  • 17
    Jun 17th
    0 Files
  • 18
    Jun 18th
    0 Files
  • 19
    Jun 19th
    0 Files
  • 20
    Jun 20th
    0 Files
  • 21
    Jun 21st
    0 Files
  • 22
    Jun 22nd
    0 Files
  • 23
    Jun 23rd
    0 Files
  • 24
    Jun 24th
    0 Files
  • 25
    Jun 25th
    0 Files
  • 26
    Jun 26th
    0 Files
  • 27
    Jun 27th
    0 Files
  • 28
    Jun 28th
    0 Files
  • 29
    Jun 29th
    0 Files
  • 30
    Jun 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close