Users login

Create an account »

JOIN XATRIX

Users login

Home » Hacking News » Remote BSD ftpd exploit (revised)

Remote BSD ftpd exploit (revised)

by phiber on April 16th, 2001 Here is a new version of turkey.c which fixes a design issue in the socket i/o which caused it to unnecessarily fail on a lot of systems. You must have an account on the system to be able to use the exploit. You could theoretically be an anonymous user with access to a writeable directory, but it would require a chroot break, which is not included in the exploit. To download, click here.





turkey2.c works by default on all unpatched FreeBSD 4.[0-2] running the
default ftp server and OpenBSD 2.8. It should work elsewhere with a tiny bit of tuning.


Download:

turkey2.c


Credit goes to fish stiqz ([email protected]).


Newsletter signup

Signup to our monthly newsletter and stay in touch with IT news!

Free E-books

We've got ebooks! But they're not online. :( Please give us a few days to bring downloads back.

Contact

Have something to say or just wanna drop us a line? Please keep this in mind: to spam, we reply with spam.

Contact us »