vuln.sg  Mini Roshutsu Game 2 -RJ01260604-

vuln.sg Vulnerability Research Advisory

AceFTP FTP-Client Directory Traversal Vulnerability

by Tan Chew Keong
Release Date: 2008-06-27

Mini Roshutsu Game 2 -RJ01260604-   [en] [jp]

Mini Roshutsu Game 2 -RJ01260604- Summary

A vulnerability has been found within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.


Mini Roshutsu Game 2 -RJ01260604- Tested Versions
Mini Roshutsu Game 2 -RJ01260604- Details

This advisory discloses a vulnerability within the FTP client in AceFTP. When exploited, this vulnerability allows an anonymous attacker to write files to arbitrary locations on a Windows user's system.

The FTP client does not properly sanitise filenames containing directory traversal sequences (forward-slash) that are received from an FTP server in response to the LIST command.

An example of such a response from a malicious FTP server is shown below.


Response to LIST (forward-slash):

-rw-r--r--    1 ftp      ftp            20 Mar 01 05:37 /../../../../../../../../../testfile.txt\r\n
 

By tricking a user to download a directory from a malicious FTP server that contains files with fowward-slash directory traversal sequences in their filenames, it is possible for the attacker to write files to arbitrary locations on a user's system with privileges of that user. An attacker can potentially leverage this issue to write files into a user's Windows Startup folder and execute arbitrary code when the user logs on.


Mini Roshutsu Game 2 -RJ01260604- POC / Test Code

Please download the POC here and follow the instructions below.

Mini Roshutsu Game 2 -rj01260604- [top] Jun 2026

⭐⭐⭐⭐☆ (4/5) – "Better, bolder, and brutally unforgiving."

The game features a dual-gauge system. Exposing the character in highly risky areas increases her excitement, unlocking new outfits or actions.

Movement requires observing NPC patterns and utilizing the environment to remain unseen. Environmental Interaction: Mini Roshutsu Game 2 -RJ01260604-

As a "Mini" game, the project scales down asset sizes to focus on tight, arcade-like loops.

The chibi pixel art (large heads, simple faces) ironically reduces visual sexual detail while the scenario remains sexually extreme. This tension creates a “cute but dangerous” aesthetic – players report less guilt than photorealistic roshutsu games, enabling repeat play. Environmental Interaction: As a "Mini" game, the project

Some of the key features of Mini Roshutsu Game 2 -RJ01260604- include:

The tension of exposure. The thrill of the crowd. Some of the key features of Mini Roshutsu

Determine which platforms Mini Roshutsu Game 2 -RJ01260604- is available on. This could include handheld consoles, PCs, or even mobile devices, depending on the game's specifications.

Stages move beyond simple streets to include multi-layered environments like schools, public transit, and commercial districts.

Each level requires the player to reach specific nodes on the map (e.g., a park bench, a convenience store aisle, or a train platform).

Mini Roshutsu Game 2 -RJ01260604- stands out as a fascinating addition to the world of gaming, particularly for those with an interest in Japanese culture and puzzle-adventure games. Its engaging gameplay, coupled with a likely rich narrative and charming presentation, makes it a title worth exploring. Whether you're a seasoned gamer looking for a new challenge or someone interested in discovering niche titles, Mini Roshutsu Game 2 -RJ01260604- offers a unique experience that could keep you entertained for hours on end. As with any game, the true experience can only be understood by playing it, so if you're intrigued, don't hesitate to dive in and explore what Mini Roshutsu Game 2 -RJ01260604- has to offer.


Mini Roshutsu Game 2 -RJ01260604- Patch / Workaround

Avoid downloading files/directories from untrusted FTP servers.


Mini Roshutsu Game 2 -RJ01260604- Disclosure Timeline

2008-06-15 - Vulnerability Discovered.
2008-06-16 - Vulnerability Details Sent to Vendor via online support form (no reply).
2008-06-18 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-25 - Vulnerability Details Sent to Vendor again via online support form (no reply).
2008-06-27 - Public Release.


Contact
For further enquries, comments, suggestions or bug reports, simply email them to