Bounce vulnerability in SpoonFTP 1.1.0.1

From: Arne Vidstrom (arne.vidstrom@NTSECURITY.NU)
Date: 01/20/02


Date:         Sun, 20 Jan 2002 03:04:39 +0100
From: Arne Vidstrom <arne.vidstrom@NTSECURITY.NU>
To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM

The vulnerability:

The FTP server is vulnerable to the FTP bounce attack, even against ports
lower than 1024.

Vendor Response:

Pi-Soft have created a new version that among other things fix this
vulnerability. Their response was very nice and quick.

/Arne Vidstrom, http://ntsecurity.nu

============================================================================
Delivery co-sponsored by VeriSign - The Internet Trust Company
============================================================================
FREE E-COMMERCE SECURITY INFRASTRUCTURE GUIDE
When building an e-commerce site, you want to start with a strong, secure
foundation. Learn how with VeriSign's FREE White Paper, "Building an
E-Commerce Trust Infrastructure." See how you can authenticate your site to
customers, use 128-Bit SSL encryption to secure your web servers, and accept
secure payments online. Click here:
http://www.verisign.com/cgi-bin/go.cgi?a=n116965650045000
============================================================================



Relevant Pages

  • Bounce vulnerability in SpoonFTP 1.1.0.1
    ... The vulnerability: ... The FTP server is vulnerable to the FTP bounce attack, ... Vendor Response: ... Pi-Soft have created a new version that among other things fix this ...
    (Bugtraq)
  • SecurityFocus Microsoft Newsletter #112
    ... MICROSOFT VULNERABILITY SUMMARY ... Northern Solutions Xeneo Web Server Denial Of Service Vulnerability ... Pablo Software Solutions FTP Server Format String Vulnerability ... NEW PRODUCTS FOR MICROSOFT PLATFORMS ...
    (Focus-Microsoft)
  • [NT] FTPServer/X Response Buffer Overflow Vulnerability
    ... to promote the most advanced vulnerability assessment solutions today. ... has been identified in FTPServer/X, which can be exploited by malicious ... * FTPServer/X - FTP Server Control and COM Object version 1.00.046 ... 11/04/2003 - Vendor notified. ...
    (Securiteam)
  • SecurityFocus Microsoft Newsletter #290
    ... Microsoft Infotech Storage Library Heap Corruption Vulnerability ... Intervations FileCopa User Command Remote Buffer Overflow Vulnerability ... XM Easy Personal FTP Server Unspecified Authentication Buffer Overflow Vulnerability ...
    (Focus-Microsoft)
  • [VulnWatch] Secunia Research: FTPServer/X Response Buffer Overflow Vulnerability
    ... FTPServer/X - FTP Server Control and COM Object v1.00.046. ... A vulnerability has been identified in FTPServer/X, ... Secunia Research. ...
    (VulnWatch)