Latest Comments
"trend is good antivirus software."
by jack | Dec 3, 2008 7:02 AM
 
"I feel it with you guys. These irritating interruptions on privacy MUST be stopped. It is a ..."
by Jan Wilmans | Dec 2, 2008 7:11 PM
 
"My AVG WILL NOT UPDATE"
by James Downs | Dec 2, 2008 5:58 AM
 
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM

Researcher discloses Microsoft FTP client flaw

  • Email a Friend
  • Print Page
Researcher discloses Microsoft FTP client flaw
By Frank Washkush Jr
Nov 30, 2007 9:25 AM
Tags: "microsoft | security" | "microsoft | security | flaw" | "microsoft | FTP | flaw"
Researcher Rajesh Sethumadhavan said Wednesday that the buffer overflow flaw, which he discovered on Nov. 20, can allow a DoS attack or the execution of arbitrary code on a victimized computer.

However, other researchers on Thursday downplayed the threat.

The vulnerability exists within the FTP Client application on Windows 2000 Server, Windows 2000 Professional and XP operating systems. Other versions may also be affected, according to the Bangalore, India-based researcher, who provided proof-of-concept code.

The flaw is caused by an error when the client validates commands such as “mget,” “dir,” “user” and “ils.” For exploitation, an attacker would have to craft a malicious payload with those commands, Sethumadhavan said.

“This vulnerability is hard to exploit since it requires social engineering and shellcode has to be injected as argument in vulnerable commands,” he said.

Ben Greenbaum, senior research manager at Symantec Security Response, said the flaw takes so much work to exploit that it should not be a concern for administrators.

“Exploitation of this issue would require a fair amount of social engineering, and it would require the user to take actions that are patently unsafe,” he said. “It would unfortunate, with all the other threats and vulnerabilities out there that need patching, if users or IT staffs spent too much time worrying about this one.”

A Microsoft representative could not be reached for comment today.

See original article on SC Magazine US

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Vulnerabilities & Exploits Whitepapers