by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
The Hobbit The Battle Of The Five Armies Tamil Dubbed Isaidub -
The Tamil dubbed version of The Hobbit: The Battle of the Five Armies on Isaidub has been a highly anticipated release, and fans are thrilled to have access to the movie in their native language. The dubbing team has done an excellent job of translating the dialogue and syncing it with the characters’ lip movements, making it a seamless viewing experience.
The Hobbit: The Battle of the Five Armies Tamil dubbed on Isaidub is a treat for fans of the fantasy genre. With its engaging storyline, stunning visuals, and memorable characters, the movie is a must-watch for anyone who loves epic adventures. By following the steps outlined above, you can easily download or stream the movie on Isaidub and enjoy it in the comfort of your own home. So, what are you waiting for? Head over to Isaidub and experience the magic of Middle-earth in Tamil. The Tamil dubbed version of The Hobbit: The
The Hobbit: The Battle of the Five Armies is an epic fantasy adventure film directed by Peter Jackson, based on the novel by J.R.R. Tolkien. The movie takes place in the fictional world of Middle-earth, where Bilbo Baggins, a hobbit, joins a group of dwarves on a quest to reclaim their treasure from the dragon Smaug. As they journey through treacherous landscapes and battle fearsome enemies, they must also confront the dark lord Sauron, who seeks to conquer all of Middle-earth. With its engaging storyline, stunning visuals, and memorable
Isaidub is a well-known website that provides access to a vast library of movies, TV shows, and music in various languages, including Tamil, Telugu, Malayalam, and more. The platform has gained a massive following in India and other countries, thanks to its extensive collection of content and user-friendly interface. Isaidub offers a wide range of movies, including Bollywood, Hollywood, and regional cinema, making it a one-stop destination for movie enthusiasts. Head over to Isaidub and experience the magic
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.