by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Zase Biology Textbook Grade 10-12 Here
The is a widely recognized and essential study reference designed to fulfill the senior secondary school biology curriculum. Developed over nine years of classroom teaching experience by its author, and published in collaboration with St. Lisbon Publications , this comprehensive textbook serves as both a foundational guide for beginners and a rigorous preparatory manual for students targeting high scores in national leaving examinations.
In the Zambian education system, "ZASE Biology" refers to the biology curriculum taught in secondary schools for (often called the Senior Secondary level). The term is strongly linked to the Zambia Association for Science Education (ZASE) , a professional body that plays a key role in supporting science teachers and shaping the science curriculum. zase biology textbook grade 10-12
They followed the lab protocol and set yeast to work in tiny vials of sugar water. The textbook’s diagrams clicked into real motion as the bubbles formed: CO2, a small and triumphant thing, rising. Amir read aloud a note scribbled in the margin near the diagram of enzymes: “Temperature matters. Too hot, and the party ends.” They laughed at the thought of molecules dancing and losing their rhythm. The is a widely recognized and essential study
Unlike international textbooks that may include extra material or miss local specifics, the ZASE textbook is built around the Zambian senior secondary biology curriculum. It covers everything from Cell Biology and Nutrition to Genetics and Ecology . In the Zambian education system, "ZASE Biology" refers
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.