exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

serv-u.25b.txt

serv-u.25b.txt
Posted Feb 4, 2000
Authored by Underground Security Systems Research

Serv-u FTP-Server v2.5b for Win9x/WinNTFTP-Server v2.5b will crash if you upload a malformed link file and type the ftp command LIST, due to overflow in Windows API SHGetPathFromIDList.

tags | exploit, overflow
systems | windows
SHA-256 | 1553e21d813e70115f971fbf6e139bf7d8dedb4efc386150d7a1b03a64116625

serv-u.25b.txt

Change Mirror Download
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Local / Remote D.o.S Attack in Serv-U FTP-Server v2.5b for
Win9x/WinNT Vulnerability

USSR Advisory Code: USSR-2000032

Release Date:
February 04, 2000

Systems Affected:
Serv-U FTP-Server v2.5b and maybe other versions.
Windows 95
Windows 98
Windows Nt 4.0 WorkStation
Windows Nt 4.0 Server


THE PROBLEM
UssrLabs found a buffer overflow, in one Windows Api
"SHGetPathFromIDList" This function
converts an item identifier list to a file system path, just one Api
who manage Links
files under windows.
If you have one malformed link file you can crash anything who try to
Translate from
.lnk file like EXPLORER.EXE. all common dialogs and so on (copy one
malformed link
file to the desktop,and you cant login intro the machine).
To made Serv-u crash just upload one malformed link file in any
serv-u
directory and type the ftp command LIST, and Server Crashh.

Note:
this overflow no work under win2k

Example Malformed link in: http://www.ussrback.com/god.lnk

Binary or source for this Exploit:

http://www.ussrback.com/

Vendor Status:
Contacted.

Vendor Url: http://ftpserv-u.deerfield.com/
Program Url: http://ftpserv-u.deerfield.com/download.cfm

Credit: USSRLABS

SOLUTION
Next version, personal code for handle links files.

Greetings:
Eeye, Attrition, w00w00, beavuh, Rhino9, ADM, L0pht, HNN,
Technotronic and
Wiretrip.

u n d e r g r o u n d s e c u r i t y s y s t e m s r e s e a r c
h
http://www.ussrback.com


-----BEGIN PGP SIGNATURE-----
Version: PGPfreeware 6.5.2 for non-commercial use <http://www.pgp.com>

iQA/AwUBOJpk5tybEYfHhkiVEQKClgCeLGzAF22XekE1PuQl1Gn0YFKWrw0AnjnW
0ERSgzfn2hLW0mykNlSgZeea
=ZU9/
-----END PGP SIGNATURE-----


Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close