# Exploit Title: Ftp Server 1.32 - Credential Disclosure # Date: 2018-05-29 # Software Link: https://play.google.com/store/apps/details?id=com.theolivetree.ftpserver # Version: 1.32 Android App # Vendor: The Olive Tree # Exploit Author: ManhNho # CVE: N/A # Category: Mobile Apps # Tested on: Android 4.4 # Description # Ftp Server 1.32 Insecure Data Storage, the result of storing confidential # information insecurely on the system i.e. poor encryption, plain text, # access control issues etc. Attacker can find out username/password of valid user via # /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml # PoC 2221 2300-2399 ManhNho 0 1 ManhNho