woah woah watch your words<br>
<br>
many people on fd make their career based on 1) and 2) so dont diss them unless you want to start an e-war<br><br><div><span class="gmail_quote">On 11/28/07, <b class="gmail_sendername">Peter Dawson</b> &lt;<a href="mailto:slash.pd@gmail.com">
slash.pd@gmail.com</a>&gt; wrote:</span><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">Yeah ..<br><br>a) &quot;Social engineer victim to open it.&quot; 
<br>b) &quot;Persuade victim to run the command &quot;<br><br>is kind funky.. <div><span class="e" id="q_11688a0a31f5d660_1"><br><br><div class="gmail_quote">On Nov 28, 2007 5:21 PM, Stan Bubrouski &lt;<a href="mailto:stan.bubrouski@gmail.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">

stan.bubrouski@gmail.com</a>&gt; wrote:<br><blockquote class="gmail_quote" style="border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">Not to mention the obvious fact that if you have to trick someone into
<br>running a batch file then you could probably just tell the genius to<br>execute a special EXE you crafted for them.<br><font color="#888888"><br>-sb<br></font><div><div></div><div><br>On Nov 28, 2007 4:43 PM, dev code &lt;
<a href="mailto:devcode29@hotmail.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">devcode29@hotmail.com</a>&gt; wrote:<br>&gt;<br>&gt; &nbsp;lolerowned, kinda like the 20 other non exploitable stack overflow
<br>&gt; exceptions that someone else has been reporting on full disclosure
<br>&gt; ________________________________<br>&gt; Date: Wed, 28 Nov 2007 09:11:30 -0600<br>&gt; From: <a href="mailto:reepex@gmail.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">reepex@gmail.com
</a><br>&gt; To: <a href="mailto:rajesh.sethumadhavan@yahoo.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">rajesh.sethumadhavan@yahoo.com
</a>; <a href="mailto:full-disclosure@lists.grok.org.uk" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">full-disclosure@lists.grok.org.uk</a><br>&gt; Subject: Re: [Full-disclosure] Microsoft FTP Client Multiple Bufferoverflow
<br>&gt; Vulnerability<br>&gt;<br>&gt;<br>&gt;
<br>&gt; so... what fuzzer that you didnt code did you use to find these amazing<br>&gt; vulns?<br>&gt;<br>&gt; Also nice &#39;payload&#39; &nbsp;in your exploits meaning &#39;nice long lists of &quot;a&quot;s&#39;. You<br>&gt; should not claim code execution when your code does not perform it.
<br>&gt;<br>&gt; Well I guess it has been good talking until your fuzzer crashes another<br>&gt; application and you copy and paste the results<br>&gt;<br>&gt;<br>&gt; On 11/28/07, Rajesh Sethumadhavan &lt;<a href="mailto:rajesh.sethumadhavan@yahoo.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">

rajesh.sethumadhavan@yahoo.com</a>&gt; wrote:<br>&gt; Microsoft FTP Client Multiple Bufferoverflow<br>&gt; Vulnerability<br>&gt;<br>&gt; #####################################################################<br>&gt;<br>&gt; XDisclose Advisory &nbsp; &nbsp; &nbsp;: XD100096
<br>&gt; Vulnerability Discovered: November 20th 2007<br>&gt; Advisory Reported &nbsp; &nbsp; &nbsp; : November 28th 2007<br>&gt; Credit &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: Rajesh Sethumadhavan<br>&gt;<br>&gt; Class &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; : Buffer Overflow<br>

&gt; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Denial Of Service<br>&gt; Solution Status &nbsp; &nbsp; &nbsp; &nbsp; : Unpatched<br>&gt; Vendor &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: Microsoft Corporation<br>&gt; Affected applications &nbsp; : Microsoft FTP Client<br>&gt; Affected Platform &nbsp; &nbsp; &nbsp; : Windows 2000 server
<br>&gt; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Windows 2000 Professional<br>&gt; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;Windows XP<br>&gt;
&nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
&nbsp; &nbsp; &nbsp;(Other Versions may be also effected)<br>&gt;<br>&gt; #####################################################################
<br>&gt;<br>&gt;<br>&gt; Overview:<br>&gt; Bufferoverflow vulnerability is discovered in<br>&gt; microsoft ftp client. Attackers can crash the ftp<br>&gt; client of the victim user by tricking the user.<br>&gt;<br>&gt;<br>

&gt; Description:<br>&gt; A remote attacker can craft packet with payload in the<br>&gt; &quot;mget&quot;, &quot;ls&quot;, &quot;dir&quot;, &quot;username&quot; and &quot;password&quot;<br>&gt; commands as demonstrated below. When victim execute
<br>&gt; POC or specially crafted packets, ftp client will<br>&gt; crash possible arbitrary code execution in contest of<br>&gt; logged in user. This vulnerability is hard to exploit<br>&gt; since it requires social engineering and shellcode has
<br>&gt; to be injected as argument in vulnerable commands.<br>&gt;<br>&gt; The vulnerability is caused due to an error in the<br>&gt; Windows FTP client in validating commands like &quot;mget&quot;,<br>&gt; &quot;dir&quot;, &quot;user&quot;, password and &quot;ls&quot;
<br>&gt;<br>&gt; Exploitation method:<br>&gt;<br>&gt; Method 1:<br>&gt; -Send POC with payload to user.<br>&gt; -Social engineer victim to open it.<br>&gt;<br>&gt; Method 2:<br>&gt; -Attacker creates a directory with long folder or
<br>&gt; filename in his FTP server (should be other than IIS<br>&gt; server)<br>&gt; -Persuade victim to run the command &quot;mget&quot;, &quot;ls&quot; or<br>&gt; &quot;dir&quot; &nbsp;on specially crafted folder using microsoft ftp
<br>&gt; client<br>&gt; -FTP client will crash and payload will get executed<br>&gt;<br>&gt;<br>&gt; Proof Of Concept:<br>&gt; <a href="http://www.xdisclose.com/poc/mget.bat.txt" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://www.xdisclose.com/poc/mget.bat.txt
</a><br>&gt; &nbsp;<a href="http://www.xdisclose.com/poc/username.bat.txt" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.xdisclose.com/poc/username.bat.txt</a><br>&gt; <a href="http://www.xdisclose.com/poc/directory.bat.txt" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://www.xdisclose.com/poc/directory.bat.txt
</a><br>&gt; <a href="http://www.xdisclose.com/poc/list.bat.txt" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.xdisclose.com/poc/list.bat.txt</a><br>&gt;<br>&gt; Note: Modify POC to connect to lab FTP Server
<br>&gt; &nbsp; &nbsp; &nbsp;(As of now it will connect to
<br>&gt; <a href="ftp://xdisclose.com" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">ftp://xdisclose.com</a>)<br>&gt;<br>&gt; Demonstration:<br>&gt; Note: Demonstration leads to crashing of Microsoft FTP
<br>&gt; Client<br>&gt;<br>&gt; Download POC rename to .bat file and execute anyone of
<br>&gt; the batch file<br>&gt; <a href="http://www.xdisclose.com/poc/mget.bat.txt" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.xdisclose.com/poc/mget.bat.txt</a><br>&gt; &nbsp;<a href="http://www.xdisclose.com/poc/username.bat.txt" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">

http://www.xdisclose.com/poc/username.bat.txt</a><br>&gt; <a href="http://www.xdisclose.com/poc/directory.bat.txt" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.xdisclose.com/poc/directory.bat.txt
</a><br>&gt; <a href="http://www.xdisclose.com/poc/list.bat.txt" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://www.xdisclose.com/poc/list.bat.txt</a><br>&gt;<br>&gt;<br>&gt; Solution:<br>&gt; No Solution<br>&gt;<br>&gt; Screenshot:<br>&gt; <a href="http://www.xdisclose.com/images/msftpbof.jpg" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://www.xdisclose.com/images/msftpbof.jpg
</a><br>&gt;<br>&gt;<br>&gt; Impact:<br>&gt; Successful exploitation may allows execution of<br>&gt; arbitrary code with privilege of currently logged in<br>&gt; user.<br>&gt;<br>&gt; Impact of the vulnerability is system level.
<br>&gt;<br>&gt;<br>&gt; Original Advisory:<br>&gt; <a href="http://www.xdisclose.com/advisory/XD100096.html" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.xdisclose.com/advisory/XD100096.html
</a><br>&gt;<br>&gt; Credits:<br>&gt; Rajesh Sethumadhavan has been credited with the
<br>&gt; discovery of this vulnerability<br>&gt;<br>&gt;<br>&gt; Disclaimer:<br>&gt; This entire document is strictly for educational,<br>&gt; testing and demonstrating purpose only. Modification<br>&gt; use and/or publishing this information is entirely on
<br>&gt; your own risk. The exploit code/Proof Of Concept is to<br>&gt; be used on test environment only. I am not liable for<br>&gt; any direct or indirect damages caused as a result of<br>&gt; using the information or demonstrations provided in
<br>&gt; any part of this advisory.<br>&gt;<br>&gt;<br>&gt;<br>&gt;<br>&gt; ____________________________________________________________________________________<br>&gt; Never miss a thing. &nbsp;Make Yahoo your home page.<br>
&gt; 
<a href="http://www.yahoo.com/r/hs" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://www.yahoo.com/r/hs</a><br>&gt;<br>&gt; _______________________________________________<br>&gt; Full-Disclosure - We believe in it.
<br>&gt; Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">
http://lists.grok.org.uk/full-disclosure-charter.html</a><br>&gt; Hosted and sponsored by Secunia - <a href="http://secunia.com/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://secunia.com/
</a><br>&gt;<br>&gt;<br>&gt; ________________________________
<br>&gt; Connect and share in new ways with Windows Live. Connect now!<br>&gt; _______________________________________________<br>&gt; Full-Disclosure - We believe in it.<br>&gt; Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">

http://lists.grok.org.uk/full-disclosure-charter.html</a><br>&gt; Hosted and sponsored by Secunia - <a href="http://secunia.com/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://secunia.com/
</a><br>&gt;<br><br>_______________________________________________
<br>Full-Disclosure - We believe in it.<br>Charter: <a href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://lists.grok.org.uk/full-disclosure-charter.html
</a><br>Hosted and sponsored by Secunia - 
<a href="http://secunia.com/" target="_blank" onclick="return top.js.OpenExtLink(window,event,this)">http://secunia.com/</a><br></div></div></blockquote></div><br><br>
</span></div><br>_______________________________________________<br>Full-Disclosure - We believe in it.<br>Charter: <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://lists.grok.org.uk/full-disclosure-charter.html" target="_blank">
http://lists.grok.org.uk/full-disclosure-charter.html</a><br>Hosted and sponsored by Secunia - <a onclick="return top.js.OpenExtLink(window,event,this)" href="http://secunia.com/" target="_blank">http://secunia.com/</a><br>
</blockquote></div><br>