vuln.sg  OnlyFans - Scarlett @scarlettkissesxo [Pack] -_...

vuln.sg Vulnerability Research Advisory

AceFTP FTP-Client Directory Traversal Vulnerability

by Tan Chew Keong
Release Date: 2008-06-27

OnlyFans - Scarlett @scarlettkissesxo [Pack] -_...   [en] [jp]

OnlyFans - Scarlett @scarlettkissesxo [Pack] -_... Summary

A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.


OnlyFans - Scarlett @scarlettkissesxo [Pack] -_... Tested Versions


OnlyFans - Scarlett @scarlettkissesxo [Pack] -_... Details

This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.

The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.

An example of such a response from a malicious FTP server is shown below.


Response to LIST (forward-slash):

-rw-r--r--    1 ftp      ftp            20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
 

By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.


OnlyFans - Scarlett @scarlettkissesxo [Pack] -_... POC / Test Code

Please download the POC here and follow the instructions below.

Onlyfans - Scarlett @scarlettkissesxo [pack] -_... -

: Howard is a vocal advocate for removing the stigma surrounding the platform. She has used her success to host content creation classes , helping others grow their following and navigate the industry. Scarlet Vas : Content and Viral Success

: Despite her success on an adult platform, she has explicitly stated, "I am not a porn star," focusing instead on "sexy stuff" and lifestyle content. General Content Strategies for Success OnlyFans - Scarlett @scarlettkissesxo [Pack] -_...

Scarlet Vas , a former actress on the Australian soap Neighbours , has built a lucrative career on OnlyFans by leaning into viral, often controversial, social media trends. : Howard is a vocal advocate for removing

: Originally a traditional model, she moved into radio presenting to better showcase her personality and musical tastes. She launched her OnlyFans to meet the demand from "loyal followers" who still wanted to see her modeling work. General Content Strategies for Success Scarlet Vas ,

For creators like Scarlett, several key strategies drive their social media and OnlyFans growth: Knowing Your Worth, OnlyFans Uncovered with Scarlett Howard


OnlyFans - Scarlett @scarlettkissesxo [Pack] -_... Patch / Workaround

Avoid downloading files/directories from untrusted FTP servers.


OnlyFans - Scarlett @scarlettkissesxo [Pack] -_... Disclosure Timeline

2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.


Contact
For further enquries, comments, suggestions or bug reports, simply email them to