Re: Buffer overflow in Microsoft ftp.exe

From: D.C. van Moolenbroek (dc.van.moolenbroek_at_chello.nl)
Date: 04/30/03

  • Next message: h1kari: "TOORCON 2003 CALL FOR PAPERS"
    To: <vuln-dev@securityfocus.com>
    Date: Wed, 30 Apr 2003 23:49:48 +0200
    
    

    "aT4r InsaN3" wrote:
    > if an attacker with axx to the system is able to modify the scriptfile he
    > can modify the script and place an evil command Quote AAAAAA..SHELLCODE...
    > and execute code with elevated privileges.

    Yes, but since he can also use the ftp client's built-in "!" command to
    execute shell commands in that case, this does not seem to be a very
    realistic scenario?

    Regards,

    David

    --
    class sig{static void main(String[]s){for// D.C. van Moolenbroek
    (int _=0;19>_;System.out.print((char)(52^// (CS student, VU, NL)
    "Y`KbddaZ}`P#KJ#caBG".charAt(_++)-9)));}}// -Java sigs look bad-
    

  • Next message: h1kari: "TOORCON 2003 CALL FOR PAPERS"

    Relevant Pages

    • ANN: vile 9.5
      ... + syntax filters can now be dynamically loaded. ... repeated '_' selects the first buffer shown. ... + modify name-completion to allow completion of filenames containing ... command rather than having it erased. ...
      (comp.editors)
    • Re: Open file and program
      ... Modify your startup code to read Command$, and parse out the filename of ... Modify the startup code to check for a previous instance. ... Dim FileNum As Long ...
      (microsoft.public.vb.general.discussion)
    • Re: Loading a particular record into a form via a command button
      ... The button wizard will ... Once you have that, modify it ... the button's Click event code, ... >command button - the command button will use the name from the combo box to ...
      (microsoft.public.access.modulesdaovba)
    • Re: How to ignore spaces in directory names?
      ... Nishi Bhonsle wrote: ... How can I modify the line below so it would ignore the spaces in the ... a command line argument. ... You need to work on debugging your problems, ...
      (perl.beginners)
    • Re: Missing devices on raid1 setup
      ... I can't modify the output of a command (unless I modify the sources of the ... you are still using sarge's mdadm then. ... ::': proud Debian developer, author, administrator, and user ...
      (Debian-User)