Ticket #2220 (closed defect: fixed)

Opened 14 years ago

Last modified 13 years ago

FTP directories containing @ result severe security risks (eg. deletion of homedir)

Reported by: paulnasca Owned by:
Priority: critical Milestone: 4.8.0-pre1
Component: mc-vfs Version:
Keywords: Cc:
Blocked By: Blocking:
Branch state: Votes for changeset:


If I login to ftp using mc (vfs FTP) and there are directories which contains the "@" character inside the directory name, MC treats it like a "hard link" which points to the home directory (remote or local - in some cases was remote directory and in other cases local directory). So, if I want to recursively delete that directory I end up recursively deleting the local or remote homedir. This does not happen to older versions of mc.

Steps to reproduce:
1) using a different client log in to your ftp server (with login and password) and create a directory "test@…" in any subdirectory
2) using midnight commander ftp plugin log in to the same server
3) browse to the "test@…" and if you enter in that directory, you'll notice that you are in the home directory (or another directory)
4) (don't do this): if you'll recursively delete, you'll end up deleting the whole directory/subdirectories where "test@…" "points" to

I am using Ubuntu 10.4 and mc -V gives this:
GNU Midnight Commander
Virtual File System: tarfs, extfs, cpiofs, ftpfs, fish
With builtin Editor
Using system-installed S-Lang library with terminfo database
With subshell support as default
With support for background operations
With mouse support on xterm
With support for X11 events
With internationalization support
With multiple codepages support
Data types: char 8 int 32 long 32 void * 32 off_t 64 ecs_char 8

Change History

comment:1 Changed 54 years ago by slavazanko

  • Blocked By 2361 removed

(In #2361) Merge changeset:f2ebbd2eb4bd9e196963ecaf1f79b31986ad64ac

For getting list of commits in branch type:

git log --pretty=oneline fcfa76b..ef676d3

comment:1 Changed 14 years ago by andrew_b

  • Blocked By 1605 added

comment:2 Changed 14 years ago by andrew_b

  • Blocked By 2361 added

comment:3 Changed 13 years ago by slavazanko

  • Status changed from new to closed
  • Resolution set to fixed

Was fixed as part of #2361

comment:4 Changed 13 years ago by slavazanko

  • Milestone changed from 4.7 to 4.8.0-pre1

comment:5 Changed 13 years ago by andrew_b

  • Blocked By 1605 removed

(In #1605) Was it fixed as a part of #2361?

Note: See TracTickets for help on using tickets.