BugTraq
Back to list
|
Post reply
[HUC] Serv-U FTPD 3.x/4.x "SITE CHMOD" Command remote exploit V1.0
Jan 26 2004 10:42PM
lion (lion cnhonker net)
/*
*-----------------------------------------------------------------------
*
* Servu.c - Serv-U FTPD 3.x/4.x "SITE CHMOD" Command
* Remote stack buffer overflow exploit
*
* Copyright (C) 2004 HUC All Rights Reserved.
*
* Author : lion
* : lion (at) cnhonker (dot) net [email concealed]
* : http://www.cnhonker.com
* Date : 2004-01-25
* : 2004-01-25 v1.0 Can attack Serv-U v3.0.0.20~v4.1.0.11
* Tested : Windows 2000 Server EN/GB
* : + Serv-U v3.0.0.20~v4.1.0.11
* Notice : *** Bug find by kkqq kkqq (at) 0x557 (dot) org [email concealed] ***
* : *** You need a valid account and a writable directory. ***
* Complie : cl Servu.c
* Usage : Servu <-i ip> <-t type> [-u user] [-p pass] [-d dir] [-f ftpport] [-c cbhost] [-s shellport]
*-----------------------------------------------------------------------
-
*/
¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡lion
¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡lion (at) cnhonker (dot) net [email concealed]
¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡2004-01-27
[ reply ]
Privacy Statement
Copyright 2010, SecurityFocus
*-----------------------------------------------------------------------
*
* Servu.c - Serv-U FTPD 3.x/4.x "SITE CHMOD" Command
* Remote stack buffer overflow exploit
*
* Copyright (C) 2004 HUC All Rights Reserved.
*
* Author : lion
* : lion (at) cnhonker (dot) net [email concealed]
* : http://www.cnhonker.com
* Date : 2004-01-25
* : 2004-01-25 v1.0 Can attack Serv-U v3.0.0.20~v4.1.0.11
* Tested : Windows 2000 Server EN/GB
* : + Serv-U v3.0.0.20~v4.1.0.11
* Notice : *** Bug find by kkqq kkqq (at) 0x557 (dot) org [email concealed] ***
* : *** You need a valid account and a writable directory. ***
* Complie : cl Servu.c
* Usage : Servu <-i ip> <-t type> [-u user] [-p pass] [-d dir] [-f ftpport] [-c cbhost] [-s shellport]
*-----------------------------------------------------------------------
-
*/
¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡lion
¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡lion (at) cnhonker (dot) net [email concealed]
¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡¡2004-01-27
[ reply ]