Denial of Service in WFTPD FTP Server
Denial of Service (DoS) condition exists in Texas Imperial Software’s FTP program, WFTPD.
May 6, 2001
Reported May 4, 2001, by JoeTesta.
VERSION AFFECTED
Texas Imperial Software’s WFTPD Program 3.00R5 for Windows 2000 and Windows NT
DESCRIPTION
ADenialof Service (DoS) condition exists in Texas Imperial Software’s FTP program,WFTPD. If an attacker connects to the FTP server and issues a change directory(CD) command that targets the FTP server’s floppy drive , the server processesthis request.
DEMONSTRATION
Joe Testa posted this proof-of-conceptcode to demonstrate this vulnerability.
VENDOR RESPONSE
Thevendor, Texas Imperial Software, willcorrect this vulnerability in a future release, version 3.1. Meanwhile, to workaround the vulnerability, use the FTP server’s BIOS settings to disable thefloppy drive.
CREDIT
Discovered by JoeTesta.
About the Author
You May Also Like