what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

efcommander.txt

efcommander.txt
Posted Aug 5, 2003
Authored by Peter Winter-Smith

EF Commander versions 3.54 and below are vulnerable to various buffer overflows that can allow for remote arbitrary code execution.

tags | advisory, remote, overflow, arbitrary, code execution
SHA-256 | 4b6a103daedde0838356670bb130997652d09b35383a7ead54a7b31c2bb79a60

efcommander.txt

Change Mirror Download
Buffer Overflow in EF Commander 3.54

Url: http://www.efsoftware.com

"EF Commander is a file manager, archiver, viewer, FTP-client for
the Windows 95/98/Me, Windows NT 4.0, Windows 2000 and Windows XP
desktop. If you've ever used and liked Norton Commander, you'll like
this dual-windowed program, which comes complete with bubble and
online help. You can search directory trees and directories and
perform actions, including Run, on files. You can also check file
attributes and edit files with search-and-replace and drag-and-drop.
Use the internal editor or associate one of your choosing to edit files,
easily view files and configure the buttons to suit your needs, and get
system and disk information with a click of the mouse."
- EFSoftware Website

Indeed it is quite remarkable, sporting a huge number of extra features
which make the $25.00 registration fee (when using paypal) a definite
bargin!

See: http://www.efsoftware.com/order/e.htm for order information.

I have noticed that EF Commander 3.54 (and possibly earlier versions)
are vulnerable to a buffer overflow in the FTP banner and other areas.
These can be replicated as follows:

FTP Banner:
===========
(EF Commander 3.54 connected...)
PADDING EBP EIP
220 [508xA][4xB][4xX] // Totalling 516+4 Bytes
(Access violation when executing 0x58585858) // 4xX

When sending the overly long packet as the FTP banner, the overflow
does not often take an immediate effect, however when sending it as
part of another response, it is immediate.

Potentially an attacker would be able to execute arbitrary code on
the system of an unsuspecting user.

Since I would not have access to a computer for a while, I thought
it best to contact the vendor, and release the advisory together,
as I very much doubt that any trouble will come from the knowledge
of this security hole, especially before a patch can be made known.

Please visit EFSoftware's website:

http://www.efsoftware.com

And check for an updated version, greater than 3.54, which will
doubtless be patched against this bug.


======================================================================


Operating system and servicepack level:
Windows 9x/Me/NT Based


Software:
EF Commander 3.54 (Possibly Earlier Versions)


Under what circumstances the vulnerability was discovered:
Under a vulnerability search.


If the vendor has been notified:
Yes, concurrent with the release of this advisory.


How to contact you for further information:
I can always be reached at peter4020@hotmail.com


Please credit this find to:
Peter Winter-Smith


Thank you for your time,
-Peter
Login or Register to add favorites

File Archive:

December 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Dec 1st
    0 Files
  • 2
    Dec 2nd
    41 Files
  • 3
    Dec 3rd
    0 Files
  • 4
    Dec 4th
    0 Files
  • 5
    Dec 5th
    0 Files
  • 6
    Dec 6th
    0 Files
  • 7
    Dec 7th
    0 Files
  • 8
    Dec 8th
    0 Files
  • 9
    Dec 9th
    0 Files
  • 10
    Dec 10th
    0 Files
  • 11
    Dec 11th
    0 Files
  • 12
    Dec 12th
    0 Files
  • 13
    Dec 13th
    0 Files
  • 14
    Dec 14th
    0 Files
  • 15
    Dec 15th
    0 Files
  • 16
    Dec 16th
    0 Files
  • 17
    Dec 17th
    0 Files
  • 18
    Dec 18th
    0 Files
  • 19
    Dec 19th
    0 Files
  • 20
    Dec 20th
    0 Files
  • 21
    Dec 21st
    0 Files
  • 22
    Dec 22nd
    0 Files
  • 23
    Dec 23rd
    0 Files
  • 24
    Dec 24th
    0 Files
  • 25
    Dec 25th
    0 Files
  • 26
    Dec 26th
    0 Files
  • 27
    Dec 27th
    0 Files
  • 28
    Dec 28th
    0 Files
  • 29
    Dec 29th
    0 Files
  • 30
    Dec 30th
    0 Files
  • 31
    Dec 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close