by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Lyric Pc Download -upd- — Sonic Boom Rise Of
The iconic blue blur, Sonic the Hedgehog, has been a staple of the gaming world for decades. With his lightning-fast speed and charming personality, Sonic has captured the hearts of gamers of all ages. One of his most exciting adventures, Sonic Boom: Rise of Lyric, is now available for PC download, offering an action-packed experience that will keep you on the edge of your seat.
Sonic Boom: Rise of Lyric PC Download - A High-Octane Adventure Awaits** Sonic Boom Rise Of Lyric Pc Download -UPD-
Sonic Boom: Rise of Lyric is a 3D platformer that follows Sonic and his friends, Tails, Knuckles, and Amy, as they embark on a thrilling quest to stop the evil Lyric from taking over the world. With a unique art style and fast-paced gameplay, this title offers a fresh take on the Sonic franchise. The iconic blue blur, Sonic the Hedgehog, has
Sonic Boom: Rise of Lyric is an exciting addition to the Sonic franchise, offering a unique blend of fast-paced gameplay, dynamic combat, and exploration. With its stunning graphics, customizable controls, and mod support, the PC version of the game is a must-play for fans of the series and newcomers alike. Download Sonic Boom: Rise of Lyric on PC today and experience the thrill of Sonic’s high-octane adventures. Sonic Boom: Rise of Lyric PC Download -
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.