|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
Re: ftp conversions exploit
Subject: Re: ftp conversions exploit
From: Alexey Chetroi (lex
TWILIGHT.TELCO.MD)
Date: Fri Dec 24 1999 - 00:51:21 CST
- Next message: Chris: "Re: Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT"
- Previous message: Richard Beels: "Re: Groupewise Web Interface"
- In reply to: David Malone: "Re: ftp conversions exploit"
- Next in thread: Gregory A Lundberg: "Re: ftp conversions exploit"
- Reply: Alexey Chetroi: "Re: ftp conversions exploit"
- Reply: Gregory A Lundberg: "Re: ftp conversions exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Wed, 22 Dec 1999, David Malone wrote:
> On Wed, Dec 22, 1999 at 04:47:25AM +0000, Desi Hacker wrote:
>
> > during the exploiting process.. the final step as instructed by the auther
> > doesn't work
> >
> > ftp> get "--use-compress-program=sh blah".tar
> > or
> > ftp> get "--use-compress-program=sh blah".tar
> >
> > instead is gives a warning of permission denied!
> > in case of anon ftp logging
>
> The ftpaccess man page contains the following example line:
>
> path-filter anonymous /etc/pathmsg ^[-A-Za-z0-9._]*$ ^\. ^-
>
> which disallows filenames starting with . or - to anonymous users.
> Maybe your ftpaccess line contains this?
it doesn't disallow filenames starting with . or -, it disallows filenames
with spaces
>
> David.
>
- Next message: Chris: "Re: Local / Remote GET Buffer Overflow Vulnerability in ZBServer 1.5 Pro Edition for Win98/NT"
- Previous message: Richard Beels: "Re: Groupewise Web Interface"
- In reply to: David Malone: "Re: ftp conversions exploit"
- Next in thread: Gregory A Lundberg: "Re: ftp conversions exploit"
- Reply: Alexey Chetroi: "Re: ftp conversions exploit"
- Reply: Gregory A Lundberg: "Re: ftp conversions exploit"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
This archive was generated by hypermail 2b27 : Fri Dec 24 1999 - 12:27:01 CST