RE: Multiple-Vendor-FTP-Vuln. (old?)

From: jeev (geonapat_private)
Date: Mon Aug 20 2001 - 14:29:30 PDT

  • Next message: Mike Jakubik: "RE: Multiple-Vendor-FTP-Vuln. (old?)"

    Tested on slack 8 with 1.2.2rc3 no problem, and with 1.2.2 no problem:
    
    ftp> ls /../*/../*/../*/../*/../*/../*/../*
    200 PORT command successful.
    150 Opening ASCII mode data connection for file list.
    226-Out of memory during globbing of /../*/../*/../*/../*/../*/../*/../*
    226 Transfer complete.
    ftp>
    
    j
    
    -----Original Message-----
    From: skip [mailto:skipat_private] 
    Sent: Monday, August 20, 2001 1:36 PM
    To: bugtraqat_private
    Subject: Re: Multiple-Vendor-FTP-Vuln. (old?)
    
    I just tested on Slackware 8 running ProFTPD Version 1.2.1
    and no bug... or at least I received the directory listings and no
    great CPU load was seen nor did my system hang. Tested via
    localhost and a remote host.
    ----
    - skip
    ----
    - p.s. we sincerely apologize to all platypus enthusiasts out
    - there who are offended by that thoughtless comment about
    - the platypi. we love the noble platypus, and it is not our
    - intention to slight these stupid creatures in any way.
    ----
    



    This archive was generated by hypermail 2b30 : Mon Aug 20 2001 - 16:08:57 PDT