by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
Anygo License Key Upd | WORKING - PICK |
For : Click the Menu icon at the top right and select Check for Updates .
Renewing or upgrading license
iToolab AnyGo is one of the most popular GPS spoofing tools globally. It helps users simulate geographic movement across iOS and Android systems safely.
Paste the alphanumeric into the designated entry box. anygo license key upd
: Using older versions of the software that are compatible with specific trial-reset tools.
: For the iOS app version, users often utilize third-party signing services like to register and install the app [9]. 🔄 Update Procedures
The license key is invalid due to a typo or mismatch. For : Click the Menu icon at the
: Most plans are set to auto-renew. If your subscription updates, you usually do not need a new key; the software will recognize the extended validity of your current account. Manual Update
When stuck on VPN setup:
: If you need to move your license to a new computer, open the menu and select "Unregister" Paste the alphanumeric into the designated entry box
A: You can uninstall the software from the old computer and register it on the new one using the same registration details.
After a major update (e.g., v4 to v5), the software might ask for your license key again. Simply copy it from your original purchase email. If you lost it, use the "Retrieve License" feature on the official website.
Disclaimer: AnyGo is designed for privacy and location simulation, not for unfair advantage in games. Use responsibly.
If you want a stress-free, secure, and working copy of AnyGo, you have three legitimate options.
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.