Go Back   FlashFXP Forums > > > >

ioFTPD General New releases, comments, questions regarding the latest version of ioFTPD.

Reply
 
Thread Tools Rate Thread Display Modes
Old 12-03-2004, 08:32 PM   #1
darko
Member
FlashFXP Registered User
ioFTPD Foundation User
 
Join Date: May 2004
Posts: 74
Default Bug with big security risk - GROUPVFSFILE

Every one can execute for example:
site change AnyGrp GROUPVSFILE ..\etc\admin.vfs

although in .ini its being disallowed:

Code:
[Change-Permissions]
groupvfsfile = M
Example logged in as normal user (no +M flag):

[code]
[R] (02:15:54) SITE CHANGE AnyGrp GROUPVFSFILE ..\etc\admin.vfs
[R] (02:15:55) 200 CHANGE Command successful.
[R] (02:16:15) CWD .


This is pretty bad :<
darko is offline   Reply With Quote
Old 12-04-2004, 03:01 AM   #2
Mouton
Posse Member
Ultimate Scripter
ioFTPD Administrator
 
Join Date: Dec 2002
Posts: 1,956
Default

Code:
[02:58:12] [R] site user
[02:58:12] [R] 200-.--------------------------------[User Info]----------------------------------.
[02:58:12] [R] 200-|                                                                             |
[02:58:12] [R] 200-| Login: Zazzle                         Group: Dolls                          |
[02:58:12] [R] 200-| Unfo : Im is cool!                    Flags: 3                              |
...
[02:58:02] [R] site change test groupvfsfile ..\vfs\patate.vfs
[02:58:02] [R] 500 groupvfsfile: Permission denied.
You ini should have [Change_Permissions], not [Change-Permissions]
This is mentioned in the upgrade thread, and probably in other forum posts.
You upgraded your .exe, but didn't change your .ini accordingly... Thus the security breach on your FTP.
Mouton is offline   Reply With Quote
Old 12-04-2004, 03:30 AM   #3
EwarWoo
Senior Member
FlashFXP Registered User
ioFTPD Registered User
 
Join Date: Oct 2002
Posts: 462
Default

A good reason not to make extreme claims in thread titles.
You just got owned darko and EVERYONE will be reading this thread
Hehe
Feel for ya fella
EwarWoo is offline   Reply With Quote
Old 12-04-2004, 10:36 PM   #4
darko
Member
FlashFXP Registered User
ioFTPD Foundation User
 
Join Date: May 2004
Posts: 74
Default

Quote:
Originally posted by EwarWoo
A good reason not to make extreme claims in thread titles.
You just got owned darko and EVERYONE will be reading this thread
Hehe
Feel for ya fella
hehe. not really.

It was an old bug i thought it didnt get fixed (http://www.ioftpd.com/board/showthre...t=GROUPVFSFILE)

It did obviously

sorry

thnx Mouton for pointing it out.
darko is offline   Reply With Quote
Reply

Tags
anygrp, change, etcadmin.vfs, groupvfsfile, [r]

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 01:01 PM.

Parts of this site powered by vBulletin Mods & Addons from DragonByte Technologies Ltd. (Details)