by Tan Chew Keong
Release Date: 2008-06-27
[en] [jp]
Summary
A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
Tested Versions
Details
This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.
The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.
An example of such a response from a malicious FTP server is shown below.
Response to LIST (forward-slash):
-rw-r--r-- 1 ftp ftp 20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.
POC / Test Code
Please download the POC here and follow the instructions below.
John Persons The Pit Download Official
Wait for John Persons to re-emerge on official platforms. In the meantime, check out similar artists like The Caretaker or Lorn to scratch that dark, ambient itch.
Despite a growing cult following, concrete information about John Persons remains elusive. Is The Pit a lo-fi industrial album, a spoken-word audio drama, or a short story collection? Depending on which fan you ask, the answer changes. However, one question dominates the search logs: John Persons The Pit Download
If you’ve been scrolling through underground music forums or indie horror literature groups lately, you might have stumbled across a cryptic title: John Persons’ The Pit . Wait for John Persons to re-emerge on official platforms
Have you found a legitimate source for the John Persons "The Pit" download? Let us know in the comments (but please, no direct piracy links). This article is for informational purposes only. Always download media from official or verified sources to avoid legal issues and cybersecurity threats. The author does not endorse illegal downloading or hosting of copyrighted material. Is The Pit a lo-fi industrial album, a
Here is everything we currently know about the release and the crucial steps to finding the file without compromising your device. Early reviewers describe The Pit as a "sonic descent into claustrophobia." Persons, known for their gritty field recordings and minimalist synthesizers, allegedly produced this 47-minute track (or collection of tracks) in a single take in upstate New York.
Persons has deleted their main social media accounts twice in the last year. Fans speculate this is part of the "artistic decay" theme of the album. As a result, links go down almost as soon as they go up. ⚠️ WARNING: The Danger of "Free" Downloads Because the official sources are inconsistent, many users turn to third-party aggregators. This is where you need to be extremely careful.
Patch / Workaround
Avoid downloading files/directories from untrusted FTP servers.
Disclosure Timeline
2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.