3D-FTP vulnerable to DoS Attack

From: Cybertrion Systems (mailinglist_at_CYBERTRION.COM)
Date: 10/20/04

  • Next message: Bill Stout: "Proactive desktop protection (need beta testers)"
    Date:         Tue, 19 Oct 2004 20:17:50 -0400
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    ##### 3D-FTP DoS Attack Vulnerability ####

    3D- FTP is an FTP client application designed for transferring files up to 20x
    faster over the Internet. 3D- FTP is vulnerable to a denial of service attack.

    =============
    Source for 3D FTP: http://www.3dftp.com

    Note: This bug had been reported to 3D FTP Support.
    ============

    ###### BUG ######
    For Bug Please Visit:
    http://www.cybertrion.com/modules.php?op=modload&name=News&file=article&sid=358&mode=thread&order=0&thold=0

    ###############

    Bug Discovered by:
    Cybertrion Systems,
    http://www.cybertrion.com

    ----------------------------------------------------------------
    This message was sent using IMP, the Internet Messaging Program.

    --
    NTBugtraq Editor's Note:
    Want to reply to the person who sent this message? This list is configured such that just hitting reply is going to result in the message coming to the list, not to the individual who sent the message. This was done to help reduce the number of Out of Office messages posters received. So if you want to send a reply just to the poster, you'll have to copy their email address out of the message and place it in your TO: field.
    --
    

  • Next message: Bill Stout: "Proactive desktop protection (need beta testers)"

    Relevant Pages

    • Re: [Full-disclosure] NetBSD FTPD and ports ***REMOTE ROOOOOT HOLE***
      ... I can confirm that this bug is present on OSX 10.3.9 at the very least. ... FTP operations by authenticated FTP users may lead to ... Multiple issues in FTP server path name handling ... It offers many enhancements over the traditional BSD ftpd, ...
      (Full-Disclosure)
    • wu-ftpd fb_realpath() off-by-one bug
      ... Wu-ftpd FTP server contains remotely exploitable off-by-one bug. ... The overflowed buffer lies on the stack. ... We investigated and successfully exploited this vulnerability on x86 based ...
      (Bugtraq)
    • Re: Directory Traversal Vulnerabilities in FTP Clients
      ... I have a bone to pick with Sun's classification of the FTP traversal ... > The Solaris ftp mget behaviour is consistent with other BSD derived ... I will simply classify this comment as "the lemming response": ... else has this bug, so we'll leave it that way'. ...
      (Bugtraq)
    • [VulnWatch] wu-ftpd fb_realpath() off-by-one bug
      ... Wu-ftpd FTP server contains remotely exploitable off-by-one bug. ... The overflowed buffer lies on the stack. ... We investigated and successfully exploited this vulnerability on x86 based ...
      (VulnWatch)
    • Re: VxWorks 5.4 FTP Server problem
      ... Take a look at the vxworks faq - this seems to be a known bug (but with ... Are you running a patched version of the FTP ... control and data connections. ...
      (comp.os.vxworks)