Re: *ALERT* BID 3581: Wu-Ftpd File Globbing Heap Corruption Vulnerability

From: Rick Kelly (rmk@toad.rmkhome.com)
Date: 11/30/01


From: Rick Kelly <rmk@toad.rmkhome.com>
Message-Id: <200111300007.fAU07Kv05883@toad.rmkhome.com>
Subject: Re: *ALERT* BID 3581: Wu-Ftpd File Globbing Heap Corruption  Vulnerability
To: David Brownlee <abs@formula1.com>
Date: Thu, 29 Nov 2001 17:07:19 -0700 (MST)

David Brownlee said:

> Can confirm 'ls ~{' runs without problem by ftp on NetBSD
> 1.5.2, 1.4.1, and 1.3.2 systems.

ftp.rmkhome.com is NetBSD/i386 1.4.1 with wuftpd 2.6.1

I applied the patches from the wuftpd ftp site.

This is what I see now:

/home/rmk> ftp ftp.rmkhome.com
Connected to tencats.rmkhome.com.
220 tencats.rmkhome.com FTP server (Version wu-2.6.1(3) Thu Nov 29 14:15:29 MST 2001) ready.

Remote system type is UNIX.
Using binary mode to transfer files.
ftp> ls ~{
500 'EPSV': command not understood.
227 Entering Passive Mode (216,17,154,228,54,106)
550 Missing }
ftp>

Looks good to me.

-- 
Rick Kelly  rmk@rmkhome.com  www.rmkhome.com



Relevant Pages

  • Re: ftp get corrupts file
    ... fedora core 3 ftp command line client. ... 227 Entering Passive Mode. ... about to open data connection. ...
    (comp.os.linux.networking)
  • Re: Listing hide files via ftp
    ... On Mar 11, 2007, at 6:01 AM, carlopmart wrote: ... Are you doing this from the server administration side, or logged into an ftp server? ... 150 Opening ASCII mode data connection for file list ... 227 Entering Passive Mode ...
    (Pen-Test)
  • Re: SuSE Linux 10.0 and IPv6 Removal
    ... Do `ftp ... 227 Entering Passive Mode ... 4096 Oct 21 17:57 SL-OSS-edge ... You are about to enter another dimension, ...
    (alt.os.linux.suse)
  • Re: ProFTPD 1.2.2rc3 Remote Server Vulnerability
    ... Is this the server dumping its core of is it your ftp client... ... > [smackenz@mainframe smackenz]$ ftp ... > 227 Entering Passive Mode. ...
    (Vuln-Dev)
  • Re: ftp/fetch "command not understood" on stable and current
    ... and EPSV, but that doesn't tell me anything. ... 220 freebsd.isc.org FTP server ready. ... 500 command not understood ... 227 Entering Passive Mode ...
    (freebsd-stable)