Re: other services vulnerable to globbing exploit?

From: Kris Kennaway (kris@obsecurity.org)
Date: 04/24/01


Date: Tue, 24 Apr 2001 11:49:38 -0700
From: Kris Kennaway <kris@obsecurity.org>
To: djs@uscreativetypes.com


On Tue, Apr 24, 2001 at 08:42:41AM -0600, Jumpin Joe wrote:
> Greetings:
>
> I have followed with interest the recent exchanges about the ftpd
> globbing vulnerability. Below is a line from the logs of a certain site
> I host. The output looks very similar to the output I've seen shared
> here about how the vulnerability is exploited. Could this be an
> (attempt) to exploit the same vulnerability through httpd? And as
> always, can this even be considered an attack? My apache and bind are
> up to date and requests like this come through at a variable rate, have
> not crashed the service, but do seem to be increasing load and eating up
> bandwidth. Thanks in advance for your consideration.

This doesn't look like a globbing attempt, but other services
certainly could be vulnerable to the buffer overflow, since glob() is
in libc (this was noted in the advisory, I believe). Recompile libc
and any statically-linked servers, etc.

Kris



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Relevant Pages

  • other services vulnerable to globbing exploit?
    ... globbing vulnerability. ... Below is a line from the logs of a certain site ... I host. ... here about how the vulnerability is exploited. ...
    (FreeBSD-Security)
  • Re: XML RPC Exploit Attack
    ... The software is new to me and I didn't know it had other logs... ... "You can find the details of the vulnerability at: ... However, for the xmlrpc.php, instead of downloading the file 'cback' or 'lupii', it now ... of course attempts to exploits the XML-RPC vulnerability. ...
    (microsoft.public.security.virus)
  • Re: weird log entries
    ... Aplogies - I'm very new to reading and understanding these ... If you see the entry does this imply someone is merely ... Or that the vulnerability ...
    (microsoft.public.inetserver.iis.security)