Re: Buffer overflow in Microsoft ftp.exe

From: rdusekat_private
Date: Wed Apr 30 2003 - 09:30:17 PDT

  • Next message: Discussion Lists: "RE: Windows XP mmc.exe Crash"

    
     ('binary' encoding is not supported, stored as-is)
    In-Reply-To: <Law8-F50RC6HixqDCZx0000a7f4at_private>
    
    >if an attacker with axx to the system is able to modify the scriptfile 
    he 
    >can modify the script and place an evil command Quote 
    AAAAAA..SHELLCODE... 
    >and execute code with elevated privileges.
    
    The attacker would only be executing code in the context of the user 
    running FTP.exe... Not necessarily elevated privileges. 
    
    -Robert Dusek
    



    This archive was generated by hypermail 2b30 : Wed Apr 30 2003 - 14:36:29 PDT