February 9th, 2002, 03:28 AM
Windows Security 2000
Microsoft has a patch for Windows 2000 and Internix 2.2 that fixes a vulnerability in the telnet protocol. Unchecked Buffer in Telnet Server Could Lead to Arbitrary Code Execution
An attacker could use this vulnerability to perform a buffer overflow attack. A successful attack could cause the Telnet Server to fail, or in some cases, could possibly allow an attacker to execute code of her choice on the system. Such code would execute using the security context of the Telnet service, but this context varies from product to product. In Windows 2000, the Telnet service always runs as System; in the Interix implementation, the administrator selects the security context in which to run as part of the installation process.
February 9th, 2002, 03:33 AM
I'm not sure if this has been reported yet but you can do the same thing with the ftp server. Don't know if they have a patch but basically it's the same exploit as the one your talking about.