[Full-disclosure] Re: another filename bypass vulnerability - fromcmd.exe

2005-11-18 Thread barabas mutsonline
#MW> I think the OP was getting at this being an AV bypass vector for worms and#MW> other malware that can interact with cmd.exe .#TZ>Hmm ok, but how can it interact when it doesn't execute using explorer.exe ? Is#the user going under Dos to execute it? How does that fit in the#scenario ?  Let's i

[Full-disclosure] freeftpd MKD buffer overflow etc...

2005-11-17 Thread barabas mutsonline
Hi,   I turned off logging on my freeftpd server as a temporary fix for the USER problem. Pfew...I felt more comfortable now. 3v17 h4x0r5 won't be able to compromise my collection of Adriana Lima pics anymore. But...while I was thinking on how to write a l33t3r PoC, I picked my nose, and a giant bo

[Full-disclosure] freeftpd USER bufferoverflow

2005-11-16 Thread barabas mutsonline
Hi,   While drooling over my new Adriana Lima wallpaper, my tongue accidentally hit my keyboard and more than 1012 chars were sent to the login screen of my freeftpd server (which i use to backup my Adriana Lima pics). Guess what...the server crashed! Luckily I attach ollydbg to every process I hav