hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

night^man
I try this on my box and it allways get crashed how i can stop it ?
help smile.gif
AlessandroIT
Update To 5.0 biggrin.gif
Hellraiseruk
agree with AlessandroIT biggrin.gif
Copkill
No way, use Serv-U 5.0 !!!
streetsurfer
whats this servu 3/4 exploit?
predx
im pretty sure you have login with an account before you can exploit so if the person cant login they cant exploit it....
liquidSilver
QUOTE
No way, use Serv-U 5.0 !!!


QUOTE
Update To 5.0 


QUOTE
agree with AlessandroIT 


...Why did we need this comment? One is egnouf.. God.. sad.gif
oYost
The problem with 5.0 is that u need a different key for each PC of a LAN :/

Use io tongue.gif
beenal
QUOTE (oYost @ Feb 13 2004, 07:21 PM)
The problem with 5.0 is that u need a different key for each PC of a LAN :/

Use io tongue.gif

can't agree to that.

Have Servu 5.0 on several Machines running, and no probs with keys...It's just a matter of setting it up the right way rolleyes.gif
oYost
blink.gif
Explain smile.gif
studnikov
if you search a key for the 5.0 .. you will notice there is a Corp key now and 5.0 doesnt need to be registered ever again .
Qlimax
everybody say this...
use the serv-u 5.0 u can download it at: www.download.com
and if u need key for that PM me i send u biggrin.gif
rockerx
serv-u 5.0 is exploitable as well!!!
as far as i know there is no exploit for serv-u 2.5e

/* ex_servu.c - Serv-U FTPD 3.x/4.x/5.x "MDTM" Command remote overflow exploit
*
* Copyright © SST 2004 All rights reserved.
*
* private
*
* BUG find by bkbll (bkbll@cnhonker.com), cool! :ppPPppPPPpp biggrin.gif
*
* code by Sam and 2004/01/07
* <chen_xiaobo@venustech.com.cn>
* <Sam@0x557.org>
*
*
* Revise History:
* 2004/01/14 add rebind shellcode :> we can bind shellport at ftpd port.
* 2004/01/09 connect back shellcode added smile.gif
* 2004/01/08 21:04 upgrade now smile.gif, we put shellcode in file parameter
* we can attack pacthed serv-U ;PPPp by airsupply
* 2004/01/08 change shellcode working on serv-u 4.0/4.1/4.2 now
* biggrin.gif thx airsupply
*
Qlimax
mmm u can do "space" an the login
ex. da da:da da@123.123.123.123:122

good luck
[eXPhase
Version 5.0.0.4 is not exploitable anymore

So upgrade smile.gif

And I've read something about a very long login message... maybe that works.

DaClueless
QUOTE (rockerx @ Mar 5 2004, 12:09 PM)
serv-u 5.0 is exploitable as well!!!
as far as i know there is no exploit for serv-u 2.5e


Here is exploit for serv-u 2.5e also, so only use: serv-u 5.0.0.4
pwnZ
disable mdtm command
TheAngel
u can set a very long welcome msg in servu like that guy sayed
then the exploit gets no where, try to do the welcome msg with colors it may help
MpR
one way to block the exploit is dont give anyone an account .. fill everything yourself .. The newer servu gets the lamer it is too use seems to get more " anti abuse " features such as multiple instances of it running key validation mdgay hashes servu blows best way to avoid the exploit is not too use it simplist aswell.. Check out slimftpd simplistic enough to use
DaClueless
QUOTE (pwnZ @ Mar 7 2004, 12:36 AM)
disable mdtm command

When ask if you can disable MDTM command to protect serv-U, here is what the author says about it:

QUOTE
Rob, Serv-U coder
No, it would not. The part that causes the crash deals with parsing the
command. That's done before the check if MDTM should be allowed to change
the file's date/time.

        Rob
        -/-

        Serv-U Author & Manager
        Cat Soft, LLC


The only way to protect from exploit is upgrade to version 5.0.0.4

I hope that helps
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.