A stack-based buffer overflow vulnerability exists in War FTP Daemon 1.65 and possibly earlier versions. The vulnerability allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors. The issue was demonstrated by Immunity using warftp_165.tar, but specific technical details about the vulnerable function or attack vector have not been disclosed.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository is a structured educational exploit-development walkthrough for CVE-2007-1567, a pre-authentication stack-based buffer overflow in War FTP Daemon 1.65. It is not a framework module; it is a standalone set of Python 3 scripts plus markdown documentation showing the full progression from initial connection testing to final remote code execution. Repository structure: the top-level README explains the vulnerability, affected product, and why the case is useful for teaching classic EIP overwrite exploitation. The 'Vulnerability/README.md' file contains the detailed methodology, including fuzzing, cyclic-pattern offset discovery, EIP control, bad-character analysis, gadget selection, and shellcode generation. The 'Vulnerability/Exploit/' directory contains seven Python scripts, each representing one stage of exploit development. Exploit flow by file: '01Python3Connection.py' verifies FTP connectivity and basic USER/PASS interaction. '02Python3Fuzzing.py' repeatedly sends increasingly large USER arguments to crash the service. '03Python3EIPOffsetDiscovery.py' sends a cyclic pattern to determine the exact EIP offset. '04Python3ControlEIP.py' confirms control of EIP using 485 bytes of padding followed by 'BBBB'. '05Python3FindBadChars.py' appends a full bytearray after the controlled EIP overwrite to identify disallowed bytes; the notes identify \x00, \x0a, \x0d, and \x40 as bad characters. '06Python3JMPESP.py' overwrites EIP with a hardcoded JMP ESP gadget from MFC42.DLL at 0x5f4ca2e3 and uses NOPs/INT3 to verify execution reaches the stack. '07Python3Shellcode.py' replaces the INT3 test bytes with a NOP sled and embedded Windows x86 shellcode, producing a working RCE payload. Main exploit capabilities: the code targets the FTP USER command on TCP port 21 and exploits the vulnerable handler before authentication. It can reproduce the crash, determine the overwrite offset, validate instruction-pointer control, identify bad characters, redirect execution through a non-ASLR module, and finally execute attacker-supplied shellcode. The documentation explicitly states the intended final outcome is a reverse shell. The final payload is operational but hardcoded to a specific legacy environment and gadget address, so it is best classified as OPERATIONAL rather than weaponized. Notable targeting details: the exploit is tailored to War FTP Daemon 1.65 on legacy Windows, especially Windows XP, because the software reportedly does not run correctly on modern Windows. Reliability depends on the presence of MFC42.DLL at the expected base/address layout and on the vulnerable service accepting oversized USER input. The repository also documents example tooling and paths for Immunity Debugger/Mona and example reverse-shell generation parameters, but those are supporting lab artifacts rather than additional exploit targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.