Faststream FTP++ Vulnerable To Denial Of Service (DoS)

Faststream FTP++ Simple FTP Server has been found to be vulnerable to a very simple denial of service attack.

Steve Manzuik

September 11, 2000

1 Min Read
ITPro Today logo

Reported September 12, 2000 by Delphis Consulting

VERSIONS AFFECTED

DESCRIPTIONRunning under Windows 2000, Faststream FTP++ 2.0, is vulnerable to a denial of service attack.  The attack causes all available CPU cycles to be consumed and requires a reboot to remedy.

DEMONSTRATION

An attacker may simply connect to port 21 (FTP) and send 4.08K of DATA as the username.  It has also been possible to crash the program with a buffer overrun but this result was random and difficult to reproduce. 

VENDOR RESPONSE

According to Delphis Consulting, the vendor has been very responsive and has released a patch available from their website, www.fastream.com

CREDITDiscovered by Delphis Consulting

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like