Re: FTP Fuzzer

"Alice Bryson" <[email protected]>
Newsgroups gmane.comp.security.vulnerabilities
Message-ID <[email protected]>
hi, could you provide more spec of using this fuzz tool, i use it to
fuzz several ftp server , but it alway crashed before ftp server does.


2005/11/13, infocus <[email protected]>:
> Hi,
>
> We have released simple and user friendly GUI FTP fuzzer tool for stress
> testing FTP server implementations. It is quite configurable tool, which
> means that you can precisely define which FTP commands will be fuzzed
> with the parameter size and test strings.
>
> Running this fuzzer against FTP server implementations resulted in
> uncovering numerous security vulnerabilities (overflows, format strings)
> in various FTP servers. After short period of fuzzing, fuzzer revealed
> buffer overflow vulnerabilities in for example:
>
> - ArgoSoft FTP Server (RNTO Unicode overflow)
> - Golden FTP Server (NLST overflow)
> - FileZilla FTP Server (MLSD)
> - FileZilla remote server interface (homemade protocol)
> - WarFTPD (various exceptions and WDM.exe overflow)
>
> You can download it from:
> http://www.infigo.hr/files/ftpfuzz.zip
>
>
> Regards,
> Leon Juranic
>


--
Homepage: http://www.lwang.org
mailto:[email protected]
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.