by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Bechain Bhabhi Uncut.mkv.mp4 Link
: A booming economy has expanded the middle class, leading to increased consumption, a focus on private education for children, and a lifestyle that balances traditional religious practices with modern technology and global trends.
: Historically, Indian families functioned as a single unit where grandparents, parents, and siblings lived under one roof, sharing a common kitchen and financial pool. The eldest male typically serves as the head of the household. Bechain bhabhi uncut.mkv.mp4
Indian family life is a rich tapestry woven from ancient traditions and rapid modernization. While the landscape is shifting from multi-generational rural households to urban nuclear units, the core values of , filial piety , and community-centric living remain steadfast. The Evolution of Household Structures : A booming economy has expanded the middle
: Life often revolves around a calendar of festivals (like Diwali or Eid ), which serve as the primary occasions for family reunions and the passing down of ancestral stories. Indian family life is a rich tapestry woven
: There is a heavy emphasis on mutual support. Financial resources are often pooled to support a relative's education or a sibling’s wedding, reflecting a "common purse" philosophy that persists in many forms.
: Modern economic pressures and migration have led to the rise of nuclear families in cities. However, even in these setups, the "extended" bond remains strong, with frequent visits and daily communication with elders. Daily Life and Social Fabric
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.