English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12017
À§Çèµµ 30
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® FTP ¼­ºñ½º´Â ºñÁ¤»óÀûÀÎ FTP ¿¬°á STAT ¿äû¿¡ ÀÇÇÑ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
FTP ¼­ºñ½º¿¡¼­ "STAT" ¸í·ÉÀº ÇöÀç ¿¬°á(connection) »óÅ Á¤º¸¸¦ ¾ò±â À§ÇØ »ç¿ëµÇ´Â ¸í·É¾îÀÌ´Ù. IIS ¼­¹ö »ó¿¡¼­ µ¿ÀÛÇÏ´Â FTP ¼­ºñ½º¿¡´Â °ø°ÝÀÚ¿¡ ÀÇÇØ ¿ø°ÝÀ¸·Î ¼­ºñ½º °ÅºÎ °ø°Ý(DoS attack)À» ¹ÞÀ» ¼ö ÀÖ´Â ¹ö±×°¡ Á¸ÀçÇϴµ¥, ÀÌ ¹ö±×·Î ÀÎÇÑ Ãë¾àÁ¡Àº °ø°ÝÀÚ°¡ Àΰ¡µÈ ·Î±×ÀÎÀ̳ª À͸í(anonymous) ·Î±×ÀÎÀ» ÅëÇØ ¼­¹ö¿¡ Á¢¼ÓÇÑ ÈÄ ´ÙÀ½°ú °°ÀÌ STAT ¸í·ÉÀ» ÀÌ¿ëÇÏ¿© ºñÁ¤»óÀûÀÎ ¿äû(request)À» ¼­¹ö¿¡ Àü´ÞÇÒ ¶§ ¹ß»ýÇÑ´Ù.

STAT *?AAAAAAAAA....[ .... A*240 ... ] ...AAAAAAAAAAAAAAA

ÀÌ ¿äû(request)Àº ½Ã½ºÅÛ¿¡ Ưº°ÇÑ ¿¡·¯ »óŸ¦ ¹ß»ý½ÃŰ°í ¹ß»ýµÈ ¿¡·¯ »óŸ¦ FTP ¼­ºñ½º°¡ ÀûÀýÈ÷ ´ëÀÀÇÏ´Â °ÍÀ» ¹æÇØÇÑ´Ù. °á°úÀûÀ¸·Î FTP ¼­ºñ½º »Ó¸¸ ¾Æ´Ï¶ó IIS À¥ ¼­ºñ½º±îÁöµµ Á¤»óÀûÀÎ ¼­ºñ½º¸¦ Áß´ÜÇÒ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ¼­ºñ½º°¡ Á¤»óÀûÀÎ µ¿ÀÛ»óÅ·Πº¹±¸µÇ±â À§ÇØ, IIS 4,0ÀÇ °æ¿ì´Â ¼öµ¿À¸·Î ¼­ºñ½º¸¦ Àç½ÃÀÛ½ÃÄÑ¾ß ÇÏÁö¸¸ IIS 5.0 À̳ª 5.1ÀÇ °æ¿ì¿¡´Â ¼­ºñ½º°¡ ÀÚµ¿À¸·Î Àç½ÃÀ۵ȴÙ.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2002-09.html
http://www.kb.cert.org/vuls/id/412203

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æûµé :
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 5.1
ÇØ°áÃ¥ ÇØ´ç ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ´Ù.

* Microsoft IIS 4.0(Windows NT 4.0 Workstation, Server, Enterprise Edition) :
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=12360

* Microsoft IIS 4.0(Windows NT 4.0 Server, Terminal Server Edition) :
http://support.microsoft.com/kb/317636

* Microsoft IIS 5.0 :
1. http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=12360 ÆäÀÌÁö¸¦ ¿ÀÇÂÇÑ´Ù.
2. ÆäÀÌÁöÀÇ ¿À¸¥ÂÊ »ó´Ü¿¡ ÀÖ´Â drop-down ¸ñ·Ï¿¡¼­ ÀÚ½ÅÀÇ ¾ð¾î¸¦ ¼±ÅÃÇÑ ÈÄ <Go>¸¦ Ŭ¸¯ÇÑ´Ù.
3. <DOWNLOAD> ¸¦ Ŭ¸¯ÇÑ´Ù.
4. ÄÄÇ»ÅÍ¿¡ ÆÐÄ¡ ÇÁ·Î±×·¥À» ´Ù¿î¹Þ¾Æ Ŭ¸¯ÇÑ´Ù.

* Microsoft IIS 5.1 :
1. http://www.microsoft.com/download/en/details.aspx?DisplayLang=en&id=13790 ÆäÀÌÁö¸¦ ¿ÀÇÂÇÑ´Ù.
2. <Download Now> ¸¦ Ŭ¸¯ÇÑ´Ù.
4. ÄÄÇ»ÅÍ¿¡ ÆÐÄ¡ ÇÁ·Î±×·¥À» ´Ù¿î¹Þ¾Æ Ŭ¸¯ÇÑ´Ù.

* IIS À¥ ¼­¹ö°¡ ±¸µ¿ ÁßÀÎ Cisco Á¦Ç° :
Ãë¾àÇÑ Á¦Ç°À̳ª ¾÷µ¥ÀÌÆ® Á¤º¸¸¦ À§ÇØ Cisco Security Advisory »çÀÌÆ®¸¦ Âü°íÇÑ´Ù.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20020415-ms02-018
°ü·Ã URL CVE-2002-0073 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)