<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META NAME="Generator" CONTENT="MS Exchange Server version 5.5.2655.35">
<TITLE>RE: [Full-Disclosure] ProFTPD-1.2.9rc2 remote root exploit</TITLE>
</HEAD>
<BODY>
<P><FONT SIZE=2>This line seems suspicious. Don't know the purpose of the shellcode, but I won't try it.</FONT>
</P>
<P><FONT SIZE=2> /* connect to the bindshell */</FONT>
<BR><FONT SIZE=2> printf("Trying to connect, please wait...\n");</FONT>
</P>
<P><FONT SIZE=2>---> void(*sleep)()=(void*)sc;sleep(5); <------- Hummm :-\</FONT>
<BR><FONT SIZE=2> if(give_me_a_shell(addr) < 0)</FONT>
</P>
<P><FONT SIZE=2> {</FONT>
<BR><FONT SIZE=2> fprintf(stderr, "Sorry, exploit didn't work.\n");</FONT>
<BR><FONT SIZE=2> return(-1);</FONT>
</P>
<P><FONT SIZE=2>The shellcode seems to be locally launched. Anybody to "decrypt" the shellcode ?</FONT>
</P>
<BR>
<BR>
<P><FONT SIZE=2>> -----Message d'origine-----</FONT>
<BR><FONT SIZE=2>> De : Andreas Gietl [<A HREF="mailto:a.gietl@e-admin.de">mailto:a.gietl@e-admin.de</A>]</FONT>
<BR><FONT SIZE=2>> Envoyé : vendredi 24 octobre 2003 15:36</FONT>
<BR><FONT SIZE=2>> À : Jean-Kevin Grosnakeur; full-disclosure@lists.netsys.com</FONT>
<BR><FONT SIZE=2>> Objet : Re: [Full-Disclosure] ProFTPD-1.2.9rc2 remote root exploit</FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> On Friday 24 October 2003 14:22, Jean-Kevin Grosnakeur wrote:</FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> this seems to delete sth on the local harddisk. anybody else </FONT>
<BR><FONT SIZE=2>> seeing this </FONT>
<BR><FONT SIZE=2>> effect?</FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> > Ladies and gentlemen, here's the source code of the exploit </FONT>
<BR><FONT SIZE=2>> for the latest</FONT>
<BR><FONT SIZE=2>> > release of ProFTPD. This is a Zero-Day private exploit, please DON'T</FONT>
<BR><FONT SIZE=2>> > REDISTRIBUTE. I will not take responsibility for any </FONT>
<BR><FONT SIZE=2>> damages which could</FONT>
<BR><FONT SIZE=2>> > result from the usage of this exploit, use it at your own risk.</FONT>
<BR><FONT SIZE=2>> ></FONT>
<BR><FONT SIZE=2>> > </FONT>
<BR><FONT SIZE=2>> --------------------------------------------------------------</FONT>
<BR><FONT SIZE=2>> ------------</FONT>
<BR><FONT SIZE=2>> ></FONT>
<BR><FONT SIZE=2>> > Have fun ! @+</FONT>
<BR><FONT SIZE=2>> ></FONT>
<BR><FONT SIZE=2>> > _________________________________________________________________</FONT>
<BR><FONT SIZE=2>> > MSN Messenger 6 <A HREF="http://g.msn.fr/FR1001/866" TARGET="_blank">http://g.msn.fr/FR1001/866</A> : plus de </FONT>
<BR><FONT SIZE=2>> personnalisation,</FONT>
<BR><FONT SIZE=2>> > plus de fun pour vous et vos amis...</FONT>
<BR><FONT SIZE=2>> ></FONT>
<BR><FONT SIZE=2>> > _______________________________________________</FONT>
<BR><FONT SIZE=2>> > Full-Disclosure - We believe in it.</FONT>
<BR><FONT SIZE=2>> > Charter: <A HREF="http://lists.netsys.com/full-disclosure-charter.html" TARGET="_blank">http://lists.netsys.com/full-disclosure-charter.html</A></FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> -- </FONT>
<BR><FONT SIZE=2>> e-admin internet gmbh</FONT>
<BR><FONT SIZE=2>> Andreas Gietl tel </FONT>
<BR><FONT SIZE=2>> +49 941 3810884</FONT>
<BR><FONT SIZE=2>> Ludwig-Thoma-Strasse 35 fax +49 </FONT>
<BR><FONT SIZE=2>> (0)1805/39160 - 29104</FONT>
<BR><FONT SIZE=2>> 93051 Regensburg mobil +49 </FONT>
<BR><FONT SIZE=2>> 171 6070008</FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> PGP/GPG-Key unter <A HREF="http://www.e-admin.de/gpg.html" TARGET="_blank">http://www.e-admin.de/gpg.html</A></FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> _______________________________________________</FONT>
<BR><FONT SIZE=2>> Full-Disclosure - We believe in it.</FONT>
<BR><FONT SIZE=2>> Charter: <A HREF="http://lists.netsys.com/full-disclosure-charter.html" TARGET="_blank">http://lists.netsys.com/full-disclosure-charter.html</A></FONT>
<BR><FONT SIZE=2>> </FONT>
<BR><FONT SIZE=2>> This mail has originated outside your organization,</FONT>
<BR><FONT SIZE=2>> either from an external partner or the Global Internet. </FONT>
<BR><FONT SIZE=2>> Keep this in mind if you answer this message.</FONT>
<BR><FONT SIZE=2>> </FONT>
</P>
</BODY>
</HTML>