Denial of Service in WFTPD FTP Server

Denial of Service (DoS) condition exists in Texas Imperial Software’s FTP program, WFTPD.

Ken Pfeil

May 6, 2001

1 Min Read
ITPro Today logo in a gray background | ITPro Today

Reported May 4, 2001, by JoeTesta.

VERSION AFFECTED

  • Texas Imperial Software’s WFTPD Program 3.00R5 for Windows 2000 and Windows NT

DESCRIPTION

 

ADenialof Service (DoS) condition exists in Texas Imperial Software’s FTP program,WFTPD. If an attacker connects to the FTP server and issues a change directory(CD) command that targets the FTP server’s floppy drive , the server processesthis request.

 

DEMONSTRATION

 

Joe Testa posted this proof-of-conceptcode to demonstrate this vulnerability.

 

VENDOR RESPONSE

 

Thevendor, Texas Imperial Software, willcorrect this vulnerability in a future release, version 3.1. Meanwhile, to workaround the vulnerability, use the FTP server’s BIOS settings to disable thefloppy drive.

 

CREDIT
Discovered by JoeTesta.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like