vuln.sg  phantombuster facebook auto liker hot

vuln.sg Vulnerability Research Advisory

AceFTP FTP-Client Directory Traversal Vulnerability

by Tan Chew Keong
Release Date: 2008-06-27

phantombuster facebook auto liker hot   [en] [jp]

phantombuster facebook auto liker hot Summary

A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.


phantombuster facebook auto liker hot Tested Versions
phantombuster facebook auto liker hot Details

This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.

The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.

An example of such a response from a malicious FTP server is shown below.


Response to LIST (forward-slash):

-rw-r--r--    1 ftp      ftp            20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
 

By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.


phantombuster facebook auto liker hot POC / Test Code

Please download the POC here and follow the instructions below.

Phantombuster Facebook Auto Liker Hot -

If this tool is so powerful, why doesn't everyone use it? Because Facebook hates it.

Social media managers are exhausted. Automating the "like" function frees up 10+ hours a week that would otherwise be spent mindlessly scrolling and double-tapping. phantombuster facebook auto liker hot


Instead of auto-liking, use Phantombuster to: If this tool is so powerful, why doesn't everyone use it

Before publishing, ensure your audience understands that "Auto Liking" carries risks. Facebook aggressively fights automation. PhantomBuster recommends "warming up" accounts and mimicking human behavior to avoid bans. Instead of auto-liking



phantombuster facebook auto liker hot Patch / Workaround

Avoid downloading files/directories from untrusted FTP servers.


phantombuster facebook auto liker hot Disclosure Timeline

2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.


Contact
For further enquries, comments, suggestions or bug reports, simply email them to