Bugtraq mailing list archives

Re: Multiple vendors FTP denial of service


From: Interstellar Overdrive <interdrive () HOME COM>
Date: Thu, 22 Mar 2001 15:30:48 +0200

a quick note, Winsock FTPD 3.00 pro and 2.41 (maybe prior) are vulnerable
to this bug as well, i tested it on a WindowsNT 4.0 box, wftpd seems to push cpu
usage to 100%, another thing concerning wftpd is that if a user isn't
restricted to his own directory, the ftpd falls in an endless loop (keeps on
listing dirs), and cpu usage is sticked on 100 % of course...so far, there
seems to be no configuration options in wftpd regarding globbing...:(

PS: Serv-U ftp doesn't seem to be vulnerable

greets,
Interstellar Overdrive


Current thread: