Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 23 Apr 2001 12:39:34 +0800
From:      Victor Sudakov <sudakov@sibptus.tomsk.ru>
To:        Andrew Barros <abarros@tjhsst.edu>
Subject:   Re: Q: Impact of globbing vulnerability in ftpd
Message-ID:  <20010423123934.A19055@sibptus.tomsk.ru>
In-Reply-To: <20010423002836.C24869@tjhsst.edu>; from abarros@tjhsst.edu on Mon, Apr 23, 2001 at 12:28:36AM -0400
References:  <20010423111632.B17342@sibptus.tomsk.ru> <20010423002836.C24869@tjhsst.edu>

next in thread | previous in thread | raw e-mail | index | archive | help
On Mon, Apr 23, 2001 at 12:28:36AM -0400, Andrew Barros wrote:
> The problem lies in that when you tell ftpd to get * it has to make a list 
> of all those files, now for a really complex pattern like 
> */../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/..
> 
> ftpd will take a long time to build the list. Thats the
> globbing vulnerability.

FreeBSD-SA-01:33 thinks otherwise:

III. Impact
Remote users may be able to execute arbitrary code on the FTP
server as the user running ftpd, usually root.
===

What you described is a DoS attack maybe, but I was speaking of
the vulnerability.

> 
> 	-ajb
> On Mon, Apr 23, 2001 at 11:16:32AM +0800, Victor Sudakov wrote:
> ->Colleagues:
> ->
> ->I do not quite understand the impact of the globbing vulnerability.
> ->
> ->As far as I understand, it can be exploited only after a user has
> ->logged in, so ftpd is already chrooted and running with the uid of
> ->the user at the moment.  What serious trouble can an attacker
> ->cause under these conditions?
> ->
> ->Thank you for any input.
> ->
> ->-- 
> ->Victor Sudakov,  VAS4-RIPE, VAS47-RIPN
> ->2:5005/149@fidonet http://vas.tomsk.ru/
> ->
> ->To Unsubscribe: send mail to majordomo@FreeBSD.org
> ->with "unsubscribe freebsd-security" in the body of the message
> ---end quoted text---
> 
> -- 
> Andrew Barros <abarros@tjhsst.edu>
> PGP Key Fingerprint:
> D3B8 0800 C45A 143E 5CF0  E112 0A1B AB36 B655 1FB8



-- 
Victor Sudakov,  VAS4-RIPE, VAS47-RIPN
2:5005/149@fidonet http://vas.tomsk.ru/

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20010423123934.A19055>