Ãë¾àÁ¡ID |
12018 |
À§Çèµµ |
30 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ÇØ´ç War-FTPd µ¥¸óÀº MKD¿Í CWD ¸í·É¾î¸¦ ÅëÇÑ ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. War-FTPd µ¥¸óÀº °³ÀÎ ¶Ç´Â Àü¹®°¡ ¿ëÀ¸·Î Á¦ÀÛµÇ¾î ³Î¸® »ç¿ëµÇ°í ÀÖ´Â, Windows Ç÷§Æû »ó¿¡¼ FTP ¼ºñ½º¸¦ Áö¿øÇÏ´Â ÇÁ¸®¿þ¾î(freeware)ÀÌ´Ù. À̵é War FTPd µ¥¸ó Áß ¹öÀü 1.67¿Í ±× ÀÌÀü ¹öÀüµé(1.6x)¿¡´Â ¿ø°ÝÀ¸·Î ¹öÆÛ ¿À¹öÇ÷οì(Buffer Overflow)¸¦ ÅëÇØ ¼ºñ½º °ÅºÎ °ø°Ý(DoS attack)À» ¹ÞÀ» ¼ö ÀÖ´Â ¹ö±×°¡ Á¸ÀçÇÑ´Ù. ÀÌ ¹ö±×¿¡ ÀÇÇÑ Ãë¾àÁ¡Àº ºÎÀûÀýÇÑ MKD¿Í CWD ¸í·ÉÀÇ °æ°è °Ë»ç(bound check)·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº ¼¹ö¸¦ Å©·¡½¬(crash)½Ã۱â À§ÇÑ ¸ñÀûÀ¸·Î Àΰ¡µÈ ·Î±×ÀÎ °èÁ¤À̳ª À͸í(anonymous) ·Î±×ÀÎÀ» ÅëÇØ ¼¹ö¿¡ Á¢¼ÓÇÑ ÈÄ, ´ÙÀ½°ú °°ÀÌ ¸í·É¾î ÀÎÀÚ·Î Áö³ªÄ¡°Ô ±ä °æ·Î¸í(passname)À» µ¡ºÙ¿© Àü¼ÛÇÑ´Ù.
CWD AAAAAA..['A'*8182]¡¦AAAAAA MKD AAAAAA..['A'*8182]¡¦AAAAAA ±× °á°ú, ¼¹ö¿¡´Â "Access Violation" ÀÌ ¹ß»ýÇÏ¿© war-ftpd.exe ÇÁ·Î¼¼½º°¡ Á¾·áµÇ°í ´õ ÀÌ»óÀÇ ¼ºñ½º°¡ ºÒ°¡´ÉÇÏ°Ô µÈ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/966 http://www.iss.net/security_center/static/4010.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
ÇØ°áÃ¥ |
War-FTP À¥ »çÀÌÆ® http://www.warftp.org/?menu=344 ¿¡¼ [War FTP Daemon], [War FTP Daemon beta (1.70)] Ç׸ñÀ» ¼±ÅÃÇÏ¿© ÀÌ Ãë¾àÁ¡ÀÌ ÇØ°áµÈ ¹öÀü 1.71 ¶Ç´Â ±× ÀÌÈÄ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2000-0131 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|