Structured lab for controlled exploitation of CVE-2025-5548 (FreeFloat FTP Server). Includes environment setup, fuzzing, EIP control, badchars detection, JMP ESP redirection, and final shellcode delivery via Python scripts.
Repository for a controlled exploitation lab of CVE-2025-5548 on FreeFloat FTP Server, running on Windows inside an isolated VM.
The project is divided into two blocks:
Environment/: environment setup (tools, IDEs, debugger, disassembler, and vulnerable apps).Exploit/: practical methodology and scripts for a complete exploitation chain of the FTP vector (MKD) associated with the CVE scenario.Build, validate, and document a reproducible exploitation chain that covers:
JMP ESP.M6/
├── README.md
├── Environment/
│ ├── 01-requirements/
│ │ └── requirements.md
│ ├── 02-programming-environment/
│ │ ├── git.md
│ │ ├── java-jdk.md
│ │ ├── netcat.md
│ │ └── python3.md
│ ├── 03-ides/
│ │ ├── notepad++.md
│ │ ├── pycharm.md
│ │ └── vscode.md
│ ├── 04-debuggers/
│ │ └── immunity-debugger.md
│ ├── 05-disassemblers/
│ │ ├── ghidra.md
│ │ └── ida-free.md
│ ├── 06-exploit-development/
│ │ └── mona-immunity.md
│ ├── 07-vulnerable-applications/
│ │ ├── freefloatftpserver.md
│ │ └── vulnserver.md
│ └── images/
│ └── README.md
└── Exploit/
├── metodologia-analisis.md
├── Scripts/
│ ├── 01_check_connection.py
│ ├── 02_fuzz_trun.py
│ ├── 03_send_pattern.py
│ ├── 04_verify_eip_control.py
│ ├── 05_send_badchars.py
│ ├── 06_test_jmp_esp.py
│ └── 07_final_payload.py
└── images/
| Block | Resource |
|---|---|
| Requirements | requirements.md |
| Programming | git.md, java-jdk.md, netcat.md, python3.md |
| IDEs | notepad++.md, pycharm.md, vscode.md |
| Debugger | immunity-debugger.md |
| Disassemblers | ghidra.md, ida-free.md |
| Exploit tooling | mona-immunity.md |
| Vulnerable apps | freefloatftpserver.md, vulnserver.md |
Full methodology: metodologia-analisis.md
Current scripts:
01_check_connection.py: validates connectivity and service banner.02_fuzz_trun.py: incremental fuzzing of the MKD command.03_send_pattern.py: sends cyclic pattern generated by Mona.04_verify_eip_control.py: validates EIP control (BBBB).05_send_badchars.py: sends bytearray.bin to detect badchars.06_test_jmp_esp.py: tests return with JMP ESP address.07_final_payload.py: sends final payload with shellcode.127.0.0.1:21.This lab is designed for technical learning, control validation, and authorized testing on your own environment. It must not be used on systems without explicit permission.
From the repo root:
cd Exploit
python .\Scripts\01_check_connection.py
python .\Scripts\02_fuzz_trun.py
python .\Scripts\03_send_pattern.py
python .\Scripts\04_verify_eip_control.py
python .\Scripts\05_send_badchars.py
python .\Scripts\06_test_jmp_esp.py
python .\Scripts\07_final_payload.py
Note: for 03_send_pattern.py and 05_send_badchars.py you must have Mona configured and the files in C:\mona\.