by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
The Merciless 2017 Wwwddrmoviesliving Hindi O Patched -
The Merciless (2017) is a highly acclaimed South Korean crime-action film directed by Byun Sung-hyun
Note: If you are looking to download or stream this movie in Hindi, the keywords you included (ddrmovies) are typically associated with pirated content sites. I cannot provide links to illegal downloads, but you can check legal platforms like Netflix, Amazon Prime, or local streaming services for the official Hindi-dubbed version if available. the merciless 2017 wwwddrmoviesliving hindi o
The Merciless (2017) is a triumph of South Korean genre filmmaking. Sul Kyung-gu and Im Si-wan deliver career-best performances, wrapped in a script that subverts the undercover-cop trope with Shakespearean tragedy. While it has gained notoriety through piracy searches (likely due to the “wwwddrmovies” term in your query), the film deserves better: legitimate discovery and discussion. The Merciless (2017) is a highly acclaimed South
If you want to experience the film's intense action and cinematography, it is highly recommended to watch it with subtitles on a verified platform like Google Play Movies officially dubbed Sul Kyung-gu and Im Si-wan deliver career-best performances,
(Yim Si-wan), a defiant new prisoner. The two form a powerful alliance behind bars, but their bond is built on a foundation of secrets: Hyun-soo is actually an undercover cop tasked with taking down Jae-ho’s crime syndicate. Why It's Worth Watching Twisted Narrative
The Merciless 2017 is a film that tackles several hard-hitting themes, including corruption, power abuse, and the struggle for justice. Through its gripping narrative, the movie sheds light on the darker aspects of human nature and the consequences of our actions.
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.