Re: Problems with various windows FTP servers

From: ByteRage (byterage@yahoo.com)
Date: 05/28/02


Date: Tue, 28 May 2002 00:32:03 -0700 (PDT)
From: ByteRage <byterage@yahoo.com>
To: bugtraq@securityfocus.com


--- SnakeByte / Eric Sesterhenn <snakebyte@gmx.de>
<snip>
> Texas Imperial Software WFTPD
> CWD ...
> CWD ....
> directory traversal possible
<snip>

I have already posted this bug to bugtraq on May 24,
2001
(cfr. http://online.securityfocus.com/bid/2779/)

The bug has been fixed in version 3.10 release 1
(cfr. http://online.securityfocus.com/bid/2779/info/)

I have verified this with WFTPD 32-bit (X86) version
3.10 release 1 9/27/2001, and this version is patched
against this bug (both CWD ... & CWD ....), since the
server returns :

501 User is not allowed to change to ... - returning
to /.

or

501 User is not allowed to change to .... - returning
to /.

(/ is the homedirectory of the user, not the
rootdirectory)

cheers,

[ByteRage]

__________________________________________________
Do You Yahoo!?
Yahoo! - Official partner of 2002 FIFA World Cup
http://fifaworldcup.yahoo.com



Relevant Pages

  • Re: Using Doxygen with Angband
    ... that really we want them in the source files instead, ... Provides an example of a documentation style. ... BUG: Brief description of bug. ...
    (rec.games.roguelike.angband)
  • Re: Realtime Preemption, 2.6.12, Beginners Guide?
    ... > Which debugging options are most useful for testing purposes? ... The new options have made the BUG warning a bit more ... send the line "unsubscribe linux-kernel" in ...
    (Linux-Kernel)
  • Re: SharedCLibrary version
    ... > the availability of a 32-bit SCL on the A9. ... > a developer beta-testing the A9, you report the bug to Adv6 in the usual ...
    (comp.sys.acorn.programmer)
  • Re: Current JSON Proposal in ES4
    ... [snip about IE for-in enumeration bug] ... [snip about object enumeration is a bad idea] ... [snip about object serialization should not be an object property] ...
    (comp.lang.javascript)
  • Re: So long and thanks for all the fish.
    ... I did report it on the A9home list to the usual deafening silence. ... they have repeated to different people that *bug* reports ... StevePotts at blastzone DOT demon STOP co DOT uk ...
    (comp.sys.acorn.misc)