🐞CVE-2025-5548
Buffer overflow in FreeFloat FTP Server 1.0

🎯 Stack Buffer Overflow Exploitation
This repository contains the documentation and practical development of a cybersecurity project focused on reverse engineering and the exploitation of memory-level vulnerabilities (Stack Buffer Overflow) in 32-bit Windows environments.
📌 Project Objective
The objective of this project is to audit, analyze, and successfully exploit the Freefloat FTP Server v1.00 software, which is known to lack modern security mitigations (such as ASLR or DEP). Throughout this repository, the entire lifecycle of the attack is documented: from setting up the laboratory environment with professional tools, to vulnerability discovery (Fuzzing), and hijacking the program's execution flow to obtain a remote console (Reverse Shell).
📂 Repository Structure
The project is divided into two main phases, each with its own detailed documentation and corresponding scripts:
-
🛠️ 01 Lab_Setup
- Contains the justification, download, and installation instructions for all the tools used during the project (Debuggers, IDEs, Interpreters, and Vulnerable Software).
- Featured tools: Immunity Debugger, IDA, Mona.py, Python 3.
-
💥 02 Vulnerability
- Contains the vulnerability analysis and the progressive development of the exploit.
- Includes Python scripts for: Fuzzing, controlling the EIP register, calculating offsets, identifying Bad Chars, and injecting the final Shellcode.
⚙️ Applied Methodology
To achieve successful exploitation, the following methodological phases were followed:
- Environment Setup: Secure deployment of the victim machine and analysis tools.
- Fuzzing (Discovery): Sending anomalous inputs to the FTP server to cause a crash (Denial of Service).
- EIP Control: Creating cyclic patterns to calculate the exact buffer size and overwrite the instruction pointer.
- Memory Analysis: Identifying restricted characters (Bad Chars) and searching for jump instructions (
JMP ESP).
- Exploitation: Generating the malicious payload (Shellcode) and achieving Remote Code Execution (RCE).