Khalil Shreateh specializes in cybersecurity, particularly as a "white hat" hacker. He focuses on identifying and reporting security vulnerabilities in software and online platforms, with notable expertise in web application security. His most prominent work includes discovering a critical flaw in Facebook's system in 2013. Additionally, he develops free social media tools and browser extensions, contributing to digital security and user accessibility.

Get Rid of Ads!


Subscribe now for only $3 a month and enjoy an ad-free experience.

Contact us at khalil@khalil-shreateh.com

 

 

VIGILANTE-2000006.txt
VIGILANTE-2000006.txt
VIGILANTE-2000006.txt

OS/2 Warp 4.5 FTP Server DoS

Advisory Code: VIGILANTE-2000006

Release VIGILANTE-2000006.txt

OS/2 Warp 4.5 FTP Server DoS

Advisory Code: VIGILANTE-2000006

Release Date:
August 15, 2000

Systems Affected:
- OS/2 Warp 4.5 FTP server V4.0/4.2
- OS/2 Warp 4.5 FTP server V4.3
- Probably other versions of the software as well.

THE PROBLEM
The FTP server that comes with OS/2 Warp 4.5 TCP/IP can be brought down by a
malicious connection attempt.

Vendor Status:
The vendor has released the patch for the problem and it contains
the following explanation of the problem: "Sending username/password
followed immediately by up to 1k of data when connecting to FTP via Telnet,
can cause a trap. ".
During testing we found that an initial connection attempt (using sockets,
telnet, ftp) using an invalid username/password combination, followed by a
second attempt, where the userfield was exceptionally long (256 bytes) would
crash the service.

Fix:
In case you are using a version prior to 4.3, please contact IBM support for
further assistance.
If you are using v4.3, you can get the patch at the following URL:
ftp://ftp.software.ibm.com/ps/products/tcpip/fixes/v4.3os2/ic27721/

Vendor URL: http://www.ibm.com
Product URL: http://www.ibm.com/software/os/warp/

Copyright VIGILANTe 2000-08-15

Disclaimer:
The information within this document may change without notice. Use of
this information constitutes acceptance for use in an AS IS
condition. There are NO warranties with regard to this information.
In no event shall the author be liable for any consequences whatsoever
arising out of or in connection with the use or spread of this
information. Any use of this information lays within the user's
responsibility.

Feedback:
Please send suggestions, updates, and comments to:

VIGILANTe
mailto: This email address is being protected from spambots. You need JavaScript enabled to view it.
http://www.vigilante.com
Social Media Share