Ãë¾àÁ¡ID |
16034 |
À§Çèµµ |
30 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ÇØ´ç Anonymous FTP ¼¹ö¿¡´Â µð·ºÅ丮 Ž»ö(Directory traversal) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â µð·ºÅ丮µéÀ» Ž»öÇϱâ À§ÇÑ (ls /../../../ ÇüÅÂÀÇ) "dot dot" ½ÃÄö½ºµéÀÌ µû¸£´Â LIST (ls) ¸í·ÉÀ» ³»¸± ¼ö ÀÖÀ¸¸ç, À̸¦ ÅëÇØ FTP Root µð·ºÅ丮ÀÇ ¿ÜºÎ ÆÄÀϵéÀ» ¸®½ºÆÃ Çϰųª »ç¿ëÀÚ ÇÏµå µð½ºÅ©¸¦ Á¶È¸ÇØ º¼ ¼ö ÀÖ´Ù.
* ÀÌ °áÇÔ°ú °ü·ÃÇÑ CVE ÂüÁ¶ »çÀÌÆ®µé: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2000-1101 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0294 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0450 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0491 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0680 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0698 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1031 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1109 http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-0877
* Âü°í »çÀÌÆ®: http://www.securiteam.com/windowsntfocus/5SP0M0055W.html http://www.securiteam.com/windowsntfocus/6W00G206AM.html http://www.der-keiler.de/Mailing-Lists/Securiteam/2001-08/0083.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: FTP ¸ðµç ¹öÀü Microsoft Windows Any version Linux Any version Unix Any version |
ÇØ°áÃ¥ |
ÆÐÄ¡³ª ¾÷±×·¹À̵带 À§ÇØ Á¦Á¶»ç¿¡ ¹®ÀÇÇØ º»´Ù. ¸¸¾à ÀÌ Ãë¾àÁ¡À» À§ÇÑ ÆÐÄ¡³ª ¾÷±×·¹À̵尡 Á¸ÀçÇÏÁö ¾ÊÀ¸¸é ´Ù¸¥ FTP ¼¹ö¸¦ »ç¿ëÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|