🧪 FreeFloat FTP Server Buffer Overflow Lab (CVE-2025-5548)

📌 Description
This lab demonstrates how to exploit a Stack Buffer Overflow vulnerability in FreeFloat FTP Server, identified as CVE-2025-5548.
The objective is to understand the complete exploitation process on vulnerable Windows applications, including:
- Fuzzing the service
- Identifying the EIP offset
- Controlling the execution flow
- Identifying bad characters
- Locating JMP ESP instructions
- Generating shellcode
- Developing a functional exploit
This lab is designed for educational purposes to learn classic memory exploitation techniques.
🎯 Lab Objectives
During this lab you will learn to:
- Analyze a vulnerable service
- Trigger a controlled crash
- Find the exact EIP offset
- Control the execution flow
- Identify bad characters
- Find gadgets in memory
- Generate shellcode with msfvenom
- Build an exploit in Python
🖥️ Lab Environment
The lab is carried out in a controlled environment with the following tools:
Victim Machine
- Windows 7 / Windows XP
- FreeFloat FTP Server
- Immunity Debugger
- Mona.py
Attacker Machine
- Kali Linux
- Python 3
- Metasploit Framework
- Netcat
- Immunity Debugger
- Mona.py
- Metasploit Framework
- msfvenom
- Python sockets
- Netcat
📂 Lab Structure
FreeFloat-BOF-Lab/
│
├── exploit/
│ ├── fuzz.py
│ ├── offset.py
│ ├── badchars.py
│ └── exploit.py
│
├── methodology/
│ └── exploitation_methodology.md
│
├── screenshots/
│
└── README.md
🔬 Methodology
The exploitation follows these steps:
- Fuzzing
- Finding EIP offset
- Controlling EIP
- Identifying bad characters
- Finding JMP ESP
- Generating shellcode
- Executing the exploit
You can find the full explanation here:
methodology/exploitation_methodology.md
🚀 Running the Exploit
Listen for the reverse connection:
nc -lvnp 443
Run the exploit:
python exploit.py
📚 Concepts Learned
- Stack Buffer Overflow
- EIP register control
- Shellcode
- Bad Characters
- JMP ESP
- Debugging on Windows
- Exploit development