Debugging

Address for Username Okay --> 00403C7D   > 68 7C164400    PUSH PCManFTP.0044167C                   ; /Arg1 = 0044167C ASCII "331 User name okay, need password.

image.png

At this address we have our comparison --> 004186B6   . 75 3B  JNZ SHORT PCManFTP.004186F3

image.png

Important Calls

image.png

Exploitation

Hello Friends

I’m Rem01x Penetration Tester Interested in Red Teaming and Reverse Engineering

In this blog we will exploit PCMan FTP server Buffer Overflow Vulnerability.

Fuzzing

Let’s start by Fuzzing the service.