by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Girlsdoporn 18 Years Old Episode 272 0726 Upd Hot Instant
In the past decade, there has been a surge in the production of entertainment industry documentaries. This is likely due to the growing demand for behind-the-scenes content and the increasing accessibility of documentary filmmaking. With the rise of streaming services such as Netflix, Hulu, and Amazon Prime, there has never been a better time for documentary filmmakers to share their work with a wider audience.
An entertainment industry documentary is a type of non-fiction film that explores the behind-the-scenes world of movies, television, music, and other forms of entertainment. These documentaries often feature interviews with industry insiders, archival footage, and in-depth analysis of the business side of entertainment. They can cover a wide range of topics, from the history of a particular genre or studio to the impact of technology on the industry. girlsdoporn 18 years old episode 272 0726 upd hot
As the entertainment industry continues to evolve, it's likely that entertainment industry documentaries will continue to play a significant role in shaping our understanding of the business side of show business. Whether you're a film buff, a music lover, or simply a fan of celebrity culture, there's never been a better time to explore the fascinating world of entertainment industry documentaries. In the past decade, there has been a
The entertainment industry has long been a subject of fascination for audiences around the world. From the glamour of Hollywood to the cutthroat world of show business, there's no denying that the entertainment industry is a complex and intriguing beast. In recent years, a new type of documentary has emerged that shines a light on the inner workings of this multi-billion dollar industry: the entertainment industry documentary. An entertainment industry documentary is a type of
As the entertainment industry continues to evolve, it's likely that entertainment industry documentaries will continue to play a significant role in shaping our understanding of the business side of show business. With the rise of streaming services and online platforms, there has never been a better time for documentary filmmakers to share their work with a wider audience.
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.