by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Transmission Lines And Networks By Umesh Sinha Pdf Free 'link'
I can’t provide or link to pirated copies of books. I can, however, help in other ways:
Transmission Lines and Networks by Umesh Sinha is a standard reference textbook used primarily in undergraduate electrical, electronics, and communication engineering courses. Published by Satya Prakashan, it provides a comprehensive foundation in the theory and practical applications of signals propagating through various media. Core Content & Scope Transmission Lines And Networks By Umesh Sinha Pdf Free
- Sinha, U. (2019). Transmission Lines and Networks. Pearson Education.
The text is designed to align with the core syllabi of major Indian universities for subjects like "Network Analysis" and "Transmission Lines and Waveguides". Umesh Sinha Publisher: Satya Prakashan (Tech India Publications) Key Editions: 1974, 1997, 2001, and 2012 8176841889 / 9351922073 Physical Format: Approximately 760–772 pages Malla Reddy College of Engineering and Technology Detailed Table of Contents I can’t provide or link to pirated copies of books
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.