TransSoft Broker FTP Vulnerable to Denial of Service

TransSoft Broker FTP can be caused to consume all available resources by sending a username of six thousand characters.

Steve Manzuik

October 17, 2000

1 Min Read
ITPro Today logo

Reported October 18, 2000 by USSR Labs

VERSIONS AFFECTED

DESCRIPTIONTransSoft's Broker FTP Server 3.x and 4.x is vulnerable to a buffer overflow that can allow a malicious attacker to consume all available memory and computing resources.

DEMONSTRATION

By sending a username of approximately 6000 characters Broker FTP Server will consume all available Windows NT resources.  For example;

C:>Telnet vulnerabletestsite.com 21Connected vulnerabletestsite.comEscape character is '^]'220 FTP Server ready [***][6000 character buffer]

VENDOR RESPONSE

The vendor, TransSoft has released a fix for this vulnerability available at; http://www.transsoft.com/broker/updates/broker40nt.exe

CREDITDiscovered by USSR Labs

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like