CVE-2010-4221 is a stack-based buffer overflow vulnerability in the pr_netio_telnet_gets function within netio.c in ProFTPD versions prior to 1.3.3c. The vulnerability is triggered when a remote attacker sends specially crafted input containing a TELNET IAC escape character to an FTP or FTPS server, leading to a buffer overflow on the stack.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This six-file standalone educational exploit repository targets CVE-2010-4221 in ProFTPD 1.3.3a on Linux. exploit.py is a raw Python socket exploit that connects to an FTP control service, receives its banner, and sends a crafted SITE command. Its odd-length command prefix changes buffer-counter parity; a TELNET escaped-IAC flood then triggers an unsigned size_t underflow in pr_netio_telnet_gets(), permitting a stack overflow. Padding reaches the hard-coded pr_cmd_read return-address slot, which is replaced with an address into an in-buffer NOP sled and x86-64 shellcode. The shellcode demonstrates execution by writing PWNED!! to standard descriptors and exiting; it does not provide an interactive shell or configurable callback. Dockerfile builds historical ProFTPD 1.3.3a from source with deliberately removed protections (-fno-stack-protector, executable stack, and no PIE), while proftpd.conf configures a standalone FTP listener on port 21. The README documents a local Docker/GDB launch configuration that disables ASLR and maps 127.0.0.1:2122 to container port 21, matching exploit.py defaults. patch.diff contains the upstream fix: a zero-length check between the two TELNET IAC-related writes/decrements, released in ProFTPD 1.3.3c. The exploit is operational only under its tightly calibrated lab assumptions because both stack base and return address are fixed.
This repository contains a single Metasploit module (modules/exploits/linux/ftp/proftp_telnet_iac.rb) that exploits a stack-based buffer overflow vulnerability in ProFTPD versions 1.3.2rc3 through 1.3.3b (CVE-2010-4221). The exploit targets the FTP service (typically on TCP port 21) by sending a large number of Telnet IAC commands, triggering a buffer overflow and allowing arbitrary code execution. The module supports multiple targets, including specific Debian and Ubuntu builds, and includes logic for brute-forcing stack cookies on systems with stack smashing protection. The payload is customizable via Metasploit and typically results in a remote shell. The code is written in Ruby and is structured as a standard Metasploit exploit module, with configuration options for payload, target selection, and brute-force attempts if needed. No hardcoded IP addresses or domains are present; the exploit is designed to be used against user-specified targets.
This repository contains a single Metasploit exploit module targeting a stack-based buffer overflow vulnerability (CVE-2010-4221) in ProFTPD server versions 1.3.2rc3 through 1.3.3b running on FreeBSD. The exploit works by sending a specially crafted FTP command containing a large number of Telnet IAC (Interpret As Command) bytes to overflow a buffer and achieve arbitrary code execution. The module supports both automatic and manual targeting, including brute-forcing return addresses for specific FreeBSD versions. The payload is customizable and encoded to avoid bad characters, allowing for execution of arbitrary shellcode (such as reverse shells) on the target. The exploit requires network access to the target's FTP service (default port 21). The code is written in Ruby and is structured as a standard Metasploit module, making it easy to use within the Metasploit framework.
This repository contains a functional exploit for CVE-2010-4221, a remote code execution vulnerability in ProFTPD. The main exploit code is in 'proftpd-exploit.c', which implements a Blind Return Oriented Programming (BROP) attack to inject and execute shellcode on a vulnerable ProFTPD server. The exploit supports multiple attack types: socket reuse shell, reverse shell, bind shell, and custom shellcode. The user provides the target IP, port, and attack type as arguments. The exploit handles network connections, payload delivery, and post-exploitation shell interaction. The 'hacking.h' file provides helper functions for error handling, memory dumping, shell interaction, and network listeners. The README.md gives usage instructions and describes the attack types. The exploit is operational and provides a shell to the attacker if successful. No hardcoded IPs or domains are present; all endpoints are supplied at runtime. The code is written in C and is intended for use against vulnerable ProFTPD servers accessible over the network.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.