📄 proftpd prior 1.5.2 pass buffer overflow.plugin
字号:
<bug_description>The target ftp server seems to be running ProFTPD prior 1.5.2 which vulnerable to a buffer overflow in the PASS command (used for password authentication). More than 12.500 characters as argument may be used for a denial of service or to run arbitrary code within the context of the server system. An attacker may gain elevated privileges and completely compromise the target host.</bug_description>
<bug_solution>Install the patches for the affected version or upgrade to the latest software version. An Intrusion Prevention System (IPS) may also be able to prevent buffer overflow vulnerabilities as like this one. The ftp server should be deactivated or de-installed if not necessary. To make it harder to find the server the daemon could be configured to listen at another port (e.g. 8021). Try to prevent unwanted connection attempts by filtering traffic with firewalling. Alternation of the application banner can confuse an attacker and let him determine the wrong software.</bug_solution>
<bug_fixing_time>Approx. 1 hour</bug_fixing_time>
<bug_exploit_availability>Yes</bug_exploit_availability>
<bug_exploit_url>http://www.snake-basket.de/bed.html</bug_exploit_url>
<bug_remote>Yes</bug_remote>
<bug_local>Yes</bug_local>
<bug_severity>High</bug_severity>
<bug_popularity>6</bug_popularity>
<bug_simplicity>7</bug_simplicity>
<bug_impact>8</bug_impact>
<bug_risk>7</bug_risk>
<bug_nessus_risk>High</bug_nessus_risk>
<bug_check_tool>Nessus is able to do the same check very accurate. See the Nessus plugin ID for more details. Furthermore other well-known vulnerability scanners (e.g. Symantec NetRecon, ISS Internet Scanner and GFI LANguard) may be able to do similar checks. Also BED by Eric Sesterhenn and Martin J. M黱ch can verify/exploit these kinds of overflow vulnerabilities automaticly.</bug_check_tool>
<source_cve>CAN-2000-0133</source_cve>
<source_securityfocus_bid>1227</source_securityfocus_bid>
<source_nessus_id>10084</source_nessus_id>
<source_literature>Hacking Intern - Angriffe, Strategien, Abwehr, Marc Ruef, Marko Rogge, Uwe Velten and Wolfram Gieseke, November 1, 2002, Data Becker, D黶seldorf, ISBN 381582284X</source_literature>
<source_misc>http://www.computec.ch</source_misc>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -