by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Beyblade Metal Fusion Psp English Patch -
A: Yes, the English patch is created by fans and is generally safe to use. However, always backup your game data and be cautious when downloading files from third-party sources.
Are you a fan of the popular Beyblade series and looking for a way to experience the thrill of Beyblade Metal Fusion on your PSP in English? Look no further! In this article, we'll take you through the world of Beyblade Metal Fusion on PSP, and provide you with a step-by-step guide on how to apply an English patch to unlock the game in your native language. beyblade metal fusion psp english patch
A: The patch may not affect online play, but it's essential to check compatibility with online features before applying the patch. A: Yes, the English patch is created by
A patch is a small software update that modifies the game's code to change its language, graphics, or gameplay mechanics. In the case of Beyblade Metal Fusion, an English patch replaces the original Japanese text and audio with translated English equivalents. This allows players to understand the game's menus, character names, and storylines, making it much easier to play and enjoy. Look no further
A: No, the patch should not affect your save data. However, it's recommended to backup your save data before applying the patch.
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.