Buffer Overflow in Ability FTP


A vulnerability has been discovered in Code Crafter's Ability FTP server version 2.3.4. This vulnerability is a buffer overflow found to be a remotely exploitable weakness in the APPE command. An attacker could craft packets and with the use of shellcode, overflow the buffer and gain root privileges on the vulnerable system.

The vendor has been notified of this vulnerability. The suggested remediation path from the vendor is to upgrade to the latest version of Ability FTP Server. Proof-of-concept code has been identified in the wild and as a result the vendor suggests upgrading to the most recent version of Ability FTP Server immediately...


Read More >>


Steganography and Corporate Spying


Steganography has been around for centuries. Steganography is the art of "hiding in plain sight." Applications of steganography in earlier times included the use of microdots (tiny photographic text) as punctuation marks in typed letters. To the unaided eye, these microdots looked no different than a comma or a period at the end of a sentence. But to the intended recipient, he/she would use a microscope to view the tiny message contained inside.

Unlike cryptography, steganography provides security through obscurity for not only the message, but also the intended recipient. Applied to current times, say a billboard or a flyer can be used ...


Read More >>


Website Relaunch


Hello and welcome to the new version of the Red Team Security website. We hope that you'll find the information listed here useful and informative. Please take a moment to explore the site.

We'd also like to make an important announcement here on the site. Just recently we've added RedTeam Labs to our website. In this section of our site, you'll find general security news, critical pieces of information security news and vulnerabilities that we've uncovered. Our hope is that you'll especially find this section useful as well. Please watch our RSS ...


Read More >>


Categories



DISCLAIMER
    The content, tools, methodologies and proof of concept code contained in these articles are in no way intended to be used for malicious intent. This information is to be used for educational purposes only. RedTeam Security does not condone the malicious use nor does it warranty the use of any of the content contained herein.


Contact Us

Phone number:
1-612-234-7848

E-mail:

info@redteamsecure.com