Re: gftp exploitable?

From: Jarno Huuskonen (Jarno.Huuskonenat_private)
Date: Wed Apr 18 2001 - 06:49:21 PDT

  • Next message: Auriemma Luigi: "Download Accelerator Pro - Bug Testing"

    On Tue, Apr 17, Richard Johnson wrote:
    > While tinkering around with gftp, we've come up with this interesting
    > result..
    >
    > (root)>gftp ftp://localhost
    > Segmentation fault
    >
    > hrmm bet ud like to know what caused that eh
    >
    > (root)>nc -l -p 21
    > %s
    > %i
    > %p
    > %x
    > %d
    > %d %d %d %d %d %d %d %d %d
    > %p %p %p %p %p %p %p %p %p
    > %s%s%s%s%s%%n%s%%n%s%%n%s%%n%s%s
    [Snip]
    
    Here's something interesting from the gftp changelog:
    Changes from 2.0.7b to 2.0.8pre1
    Fixed format string security problem in logging of ftp and http responses
    
    Before noticing the changlog I had a quick peek at gftp-2.0.7b source
    and at least these lines seem to contain format string errors:
    rfc2068.c:438,505
    rfc959.c:1177
    transfer_gui.c:1177
    
    -Jarno
    
    --
    Jarno Huuskonen - System Administrator   |  Jarno.Huuskonenat_private
    University of Kuopio - Computer Center   |  Work:   +358 17 162822
    PO BOX 1627, 70211 Kuopio, Finland       |  Mobile: +358 40 5388169
    



    This archive was generated by hypermail 2b30 : Wed Apr 18 2001 - 08:45:56 PDT