vuln.sg  kaytee carter

vuln.sg Vulnerability Research Advisory

AceFTP FTP-Client Directory Traversal Vulnerability

by Tan Chew Keong
Release Date: 2008-06-27

kaytee carter   [en] [jp]

kaytee carter Summary

A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.


kaytee carter Tested Versions


kaytee carter Details

This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.

The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.

An example of such a response from a malicious FTP server is shown below.


Response to LIST (forward-slash):

-rw-r--r--    1 ftp      ftp            20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
 

By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.


kaytee carter POC / Test Code

Please download the POC here and follow the instructions below.

Kaytee Carter < DIRECT FULL REVIEW >

Note: This is tailored if you are referring to the Kaytee who serves as a Council Member in Oneonta, NY.

#NightShift #RegisteredNurse #CabinCrew #13HourShift #ShiftWorkReality Option 4: Community Advocacy (Local Council Focus)

Grateful to represent the 4th Ward! 🏛️ Working hard to make sure our community’s voice is heard on the issues that matter most, from local infrastructure to public safety. Let’s keep working together to make our city the best it can be. 🤝 kaytee carter

Real talk: The journey through grief isn't a straight line. 🕊️ Exploring the landscape of loss, especially child loss, has changed my perspective on everything I do. If you’re navigating your own "quiet" battles today, just know you’re not alone. We’re all just doing our best to heal, one day at a time.

3 AM thoughts from the break room. ☕️ Living for those 13-hour shifts where the makeup stays put but the energy... not so much. 😅 To all my fellow night shifters and long-haulers, we see you! What’s your go-to "stay awake" snack? Note: This is tailored if you are referring

#KayteeCarter #FlightAttendantRN #CabinCrewLife #NurseLife #TravelNurse #WomenInMedicine Option 2: Personal (Grief & Healing Journey)

#GriefJourney #Healing #PersonalGrowth #KayteeCarter #LossAndLove Option 3: Relatable (Night Shift/Shift Work Vibes) Let’s keep working together to make our city

Switching from flight decks to floor shifts! ✈️🏥 Balancing life as a Cabin Crew member and an RN isn't always easy, but I wouldn't trade the views—or the chance to help people—for anything. Whether I’m at 30,000 feet or in the ER, the mission is the same: keeping everyone safe and cared for. 💙


kaytee carter Patch / Workaround

Avoid downloading files/directories from untrusted FTP servers.


kaytee carter Disclosure Timeline

2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.


Contact
For further enquries, comments, suggestions or bug reports, simply email them to