Netwin SurgeFTP Server MS-DOS Device Name Denial of Service Vulnerability
BID:2891
Info
Netwin SurgeFTP Server MS-DOS Device Name Denial of Service Vulnerability
| Bugtraq ID: | 2891 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 19 2001 12:00AM |
| Updated: | Jun 19 2001 12:00AM |
| Credit: | Reported to bugtraq by "SDL Office" <[email protected]> on June 18, 2001. |
| Vulnerable: |
NetWin SurgeFTP 2.0 a Win 95/98 NetWin SurgeFTP 1.0 b Win 95/98 |
| Not Vulnerable: |
NetWin SurgeFTP 2.0 b Win 95/98 |
Discussion
Netwin SurgeFTP Server MS-DOS Device Name Denial of Service Vulnerability
SurgeFTP is a multiplatform FTP server from Netwin Software, with versions supporting Windows NT, 2000, 95 and 98 as well as RedHat Linux 5-7 and FreeBSD.
By attempting to open a directory named for certain MS-DOS devicenames, a remote attacker can cause Windows versions of SurgeFTP to crash, requiring a restart.
SurgeFTP is a multiplatform FTP server from Netwin Software, with versions supporting Windows NT, 2000, 95 and 98 as well as RedHat Linux 5-7 and FreeBSD.
By attempting to open a directory named for certain MS-DOS devicenames, a remote attacker can cause Windows versions of SurgeFTP to crash, requiring a restart.
Exploit / POC
Netwin SurgeFTP Server MS-DOS Device Name Denial of Service Vulnerability
(courtesy SDL Office <[email protected]>):
Connect to the server with anonymous and type cd con/con
(courtesy SDL Office <[email protected]>):
Connect to the server with anonymous and type cd con/con
References
Netwin SurgeFTP Server MS-DOS Device Name Denial of Service Vulnerability
References:
References:
- NetWin Homepage (NetWin Limited)