FTP.EXE format string vulnerability

From: ByteRage (byterageat_private)
Date: Sun Jun 10 2001 - 02:07:50 PDT

  • Next message: ByteRage: "Re:FTP.EXE format string vulnerability"

    It probably doesn't matter much,
    but besides the buffer overflow problem announced by
    Eliel C. Sardaņons, FTP.EXE also contains format
    string vulnerabilities :
    
    example :
    
    QUOTE GET %x
    
    the %x will be changed into a hex number, as you might
    see in the FTP Server logs
    Not a big deal but its annoying if you want to check
    *servers* for format string vulnerabilities... :(
    
    
    
    __________________________________________________
    Do You Yahoo!?
    Get personalized email addresses from Yahoo! Mail - only $35 
    a year!  http://personal.mail.yahoo.com/
    



    This archive was generated by hypermail 2b30 : Sun Jun 10 2001 - 17:46:18 PDT