Re: [patch] ProFTPd remote root exploit

1999-09-04 Thread Dan Stromberg
Jordan Ritter wrote: > > On Mon, 30 Aug 1999, Nic Bellamy wrote: > > > tracked this problem to an sprintf() into a buffer on the stack > > in the log_xfer() routine in src/log.c. Gotta love it. Sigh. > > What's interesting to note is that I notified the contact at ProFTPd of > this exact ove

Re: [patch] ProFTPd remote root exploit

1999-09-01 Thread Jordan Ritter
On Mon, 30 Aug 1999, Nic Bellamy wrote: > tracked this problem to an sprintf() into a buffer on the stack > in the log_xfer() routine in src/log.c. Gotta love it. Sigh. What's interesting to note is that I notified the contact at ProFTPd of this exact overflow back during the last ftpd fia

[patch] ProFTPd remote root exploit

1999-08-30 Thread Nic Bellamy
Hi, tracked this problem to an sprintf() into a buffer on the stack in the log_xfer() routine in src/log.c. Gotta love it. Sigh. Attached patch against 1.2.0pre3a should fix it (it does the trick here), although it does still leave ugly stuff in your xferlog. The patch should also apply t