by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
For Photoshop Crack — Recovery Toolbox
As a graphic designer, photographer, or digital artist, you understand the importance of having access to your files, especially when working on a critical project. However, file corruption or damage can occur at any time, causing frustration and potentially leading to significant losses. This is where Recovery Toolbox For Photoshop Crack comes into play, offering a reliable solution to repair and recover damaged Photoshop files.
Recovery Toolbox For Photoshop Crack: A Comprehensive Solution for Damaged Files** Recovery Toolbox For Photoshop Crack
Recovery Toolbox For Photoshop is a specialized tool designed to repair and recover corrupted or damaged Adobe Photoshop files (PSD). The software is capable of handling a wide range of file formats, including PSD, PDD, and PSB. With its advanced algorithms and intuitive interface, Recovery Toolbox For Photoshop makes it easy to restore your files, even if they have been severely damaged or corrupted. As a graphic designer, photographer, or digital artist,
Recovery Toolbox For Photoshop Crack is a reliable and efficient solution for repairing and recovering damaged Photoshop files. With its advanced algorithms and user-friendly interface, the software makes it easy to restore your files, saving you time and effort. Whether you’re a professional graphic designer, photographer, or digital artist, Recovery Toolbox For Photoshop is an essential tool to have in your toolkit. Recovery Toolbox For Photoshop Crack is a reliable
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.