|
Brought to you by:
Suppliers of:
|
|
|
| |
"BulletProof FTP Server is the most simple and powerful FTP server to install and manage. Total control over connected users and where your files go. All features available from an easy to use graphical interface! The most BulletProof way to distribute files."
When the BPFTPServer service is installed and running as LocalSystem it is possible to manipulate the administrative interface in such a way that it will allow a local user to escalate his privileges to that of the LocalSystem account. |
| |
Credit:
The information has been provided by Reed Arvin.
|
| |
Vulnerable Systems:
* BulletProof FTP Server version 2.4.0.31
Exploit:
1. Right click the BulletProof FTP Server tray icon and click Show Server.
2. Click the Help icon.
3. Internet Explorer will open (running under the context of the LocalSystem account). Click File, Click Open.
4. Click Browse.
5. Change Files of type: to All Files, navigate to the system32 directory and locate cmd.exe. Right click cmd.exe and choose Open.
The result is a command prompt running under the context of the LocalSystem account.
|
|
|
|
|