The OpenNET Project
 
Search (keywords):  SOFT ARTICLES TIPS & TRICKS SECURITY
LINKS NEWS MAN DOCUMENTATION


[NT] Buffer Overflow in Whisper FTP Surfer


<< Previous INDEX Search src Set bookmark Go to bookmark Next >>
Date: 20 Jul 2004 10:01:01 +0200
From: SecuriTeam <[email protected]>
To: [email protected]
Subject: [NT] Buffer Overflow in Whisper FTP Surfer

The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion

The SecuriTeam alerts list - Free, Accurate, Independent.

Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html 

- - - - - - - - -



  Buffer Overflow in Whisper FTP Surfer
------------------------------------------------------------------------


SUMMARY

 <http://www.whispertech.com/>; Whisper FTP Surfer is "a freeware FTP 
client for Windows". A buffer overflow occurs when trying to open a file 
with a long name from an FTP Server.

DETAILS

Vulnerable Systems:
 * Whisper FTP Surfer version 1.0.7

For common extension (as .txt) FTP Surfer create a temporary file and 
tries to open it. When closing the FTP Surfer, it tries to delete the 
temporary file. The long name of the file added to the name of the 
temporary folder overflows the buffer.

Proof of concept:
Create a file with a very long name with the ".txt" extension, put it on 
an FTP Server and try to open it from FTP Surfer, you'll get an error 
message: "Unable to execute program". Then when you close the FTP Surfer 
the EIP will be invalid.


ADDITIONAL INFORMATION

The information has been provided by  <mailto:[email protected]> 
Komrade.




This bulletin is sent to members of the SecuriTeam mailing list. To unsubscribe from the list, send mail with an empty subject line and body to: [email protected] In order to subscribe to the mailing list, simply forward this email to: [email protected]

DISCLAIMER: The information in this bulletin is provided "AS IS" without warranty of any kind. In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.

<< Previous INDEX Search src Set bookmark Go to bookmark Next >>



Партнёры:
PostgresPro
Inferno Solutions
Hosting by Hoster.ru
Хостинг:

Закладки на сайте
Проследить за страницей
Created 1996-2025 by Maxim Chirkov
Добавить, Поддержать, Вебмастеру