by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Kaytee Carter < DIRECT FULL REVIEW >
Note: This is tailored if you are referring to the Kaytee who serves as a Council Member in Oneonta, NY.
#NightShift #RegisteredNurse #CabinCrew #13HourShift #ShiftWorkReality Option 4: Community Advocacy (Local Council Focus)
Grateful to represent the 4th Ward! 🏛️ Working hard to make sure our community’s voice is heard on the issues that matter most, from local infrastructure to public safety. Let’s keep working together to make our city the best it can be. 🤝 kaytee carter
Real talk: The journey through grief isn't a straight line. 🕊️ Exploring the landscape of loss, especially child loss, has changed my perspective on everything I do. If you’re navigating your own "quiet" battles today, just know you’re not alone. We’re all just doing our best to heal, one day at a time.
3 AM thoughts from the break room. ☕️ Living for those 13-hour shifts where the makeup stays put but the energy... not so much. 😅 To all my fellow night shifters and long-haulers, we see you! What’s your go-to "stay awake" snack? Note: This is tailored if you are referring
#KayteeCarter #FlightAttendantRN #CabinCrewLife #NurseLife #TravelNurse #WomenInMedicine Option 2: Personal (Grief & Healing Journey)
#GriefJourney #Healing #PersonalGrowth #KayteeCarter #LossAndLove Option 3: Relatable (Night Shift/Shift Work Vibes) Let’s keep working together to make our city
Switching from flight decks to floor shifts! ✈️🏥 Balancing life as a Cabin Crew member and an RN isn't always easy, but I wouldn't trade the views—or the chance to help people—for anything. Whether I’m at 30,000 feet or in the ER, the mission is the same: keeping everyone safe and cared for. 💙
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.