by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Mpl Studios Anya Caressing The Breeze S7nt4x Fixed Info
"Anya Caressing The Breeze S7nt4x" is a multimedia project that defies easy categorization. At its core, it's an animated short film that follows the journey of a young woman named Anya as she navigates a fantastical landscape filled with whispering winds, luminous skies, and mystical creatures. However, the project is so much more than just a traditional animated film. It's an immersive experience that combines stunning visuals, haunting sound design, and a narrative that blurs the lines between reality and fantasy.
: When dealing with content that may feature adult themes, intimacy, or nudity, it's essential for producers and consumers to be aware of the legal and ethical considerations, including consent, age verification, and compliance with local laws and platform guidelines. MPL Studios Anya Caressing The Breeze S7nt4x
: Often utilizing soft blues, whites, and natural skin tones, the series aims for a timeless, "editorial" look rather than traditional high-contrast glamour. "Anya Caressing The Breeze S7nt4x" is a multimedia
: The set includes high-definition photography and 4K video clips, emphasizing detail and texture in a professional studio-quality production. It's an immersive experience that combines stunning visuals,
🚩 If you're looking for the high-quality original, checking the studio’s official archives is the safest way to avoid low-res rips or security risks.
, recognized in the industry for her expressive, fluid, and graceful presence.
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.