vendor:
BisonFTP Server
by:
localh0t
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: BisonFTP Server
Affected Version From: BisonFTP Server <=v3.5
Affected Version To: BisonFTP Server <=v3.5
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows XP SP3 Spanish
2011
BisonFTP Server <=v3.5 Remote Buffer Overflow Exploit
This exploit targets BisonFTP Server version 3.5 and below. It allows an attacker to execute arbitrary code on the target machine by sending a specially crafted buffer overflow payload. The exploit connects to the target host and sends the payload. The payload consists of 1092 bytes of padding followed by a 368-byte shellcode. The shellcode is responsible for opening a shell on port 4444. The exploit has been tested on Windows XP SP3 Spanish (No DEP), but may work on other versions as well.
Mitigation:
Upgrade BisonFTP Server to a version higher than 3.5, if available. Disable unnecessary services and apply strict firewall rules to limit incoming connections.