by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Ag Mothership Font 100%
The Ag Mothership font is a modern, sans-serif typeface designed by [Foundry/Designer]. Launched in [Year], this font has quickly gained popularity among designers, agencies, and brands due to its clean lines, elegant curves, and exceptional legibility. Ag Mothership is a versatile font that can be used for a wide range of applications, from digital interfaces and advertising to editorial design and branding.
In the world of typography, fonts play a crucial role in communicating messages, evoking emotions, and setting the tone for a brand or design. With the ever-evolving landscape of digital design, the demand for unique, versatile, and high-quality fonts has never been higher. One font that has been making waves in the design community is the Ag Mothership font. In this article, we'll take a closer look at this remarkable typeface, its features, and why it's becoming a go-to choice for designers and brands alike. ag mothership font
The Ag Mothership font is a game-changing typeface that is quickly becoming a go-to choice for designers and brands. Its clean design, exceptional legibility, and versatility make it perfect for a wide range of applications, from digital design to print materials. Whether you're looking to establish a strong visual identity, create a stylish digital interface, or simply want a font that will stand the test of time, Ag Mothership is definitely worth considering. The Ag Mothership font is a modern, sans-serif
The Ag Mothership font can be purchased and downloaded from [Foundry/Designer website or online marketplaces]. Prices vary depending on the license and intended use, but with its exceptional quality and versatility, this font is a worthwhile investment for any designer or brand. In the world of typography, fonts play a
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.