by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Ssis777 Yua Mikami023049 Min Verified Best -
In the vast landscape of online media, generic searches for public figures like Yua Mikami yield millions of broad results ranging from social media updates to news articles. For enthusiasts, collectors, or digital archivists looking for precise content, broad terms are highly inefficient.
Mikami quickly became the top-selling performer of the late 2010s and early 2020s, with her physical and digital releases consistently breaking pre-order records. 3. Return to Mainstream Music & Entrepreneurship ssis777 yua mikami023049 min verified
The Enduring Legacy of Yua Mikami: Exploring the Phenomenon of SSIS-777 and Creator Content In the vast landscape of online media, generic
The query "ssis777 yua mikami023049 min verified" reveals how modern audiences track down specific content. In the Japanese video studio cataloging system, "SSIS-777" refers to a highly celebrated, feature-length release starring Mikami. Why do specific codes like this go viral? Why do specific codes like this go viral
If we were to speculate that "ssis777," "yua mikami," and "min verified" are related to a person or character's identifier, username, and verification status on a platform:
The popularity of SSIS777 and Yua Mikami has had a significant impact on the adult entertainment industry. Their contributions have helped to:
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.