English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16035
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç Anonymous FTP ¼­¹ö¿¡´Â µð·ºÅ丮 Ž»ö(Directory traversal) Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â µð·ºÅ丮µéÀ» Ž»öÇϱâ À§ÇÑ (cd /../../../ ÇüÅÂÀÇ) "dot dot" ½ÃÄö½ºµéÀÌ µû¸£´Â CWD (cd) ¸í·ÉÀ» ³»¸± ¼ö ÀÖÀ¸¸ç, À̸¦ ÅëÇØ FTP Root µð·ºÅ丮ÀÇ ¿ÜºÎ ÆÄÀϵéÀ» ´Ù¿î·Îµå ȤÀº ¾÷·Îµå ÇÒ ¼ö ÀÖ´Ù.

* ÀÌ °áÇÔ°ú °ü·ÃÇÑ CVE ÂüÁ¶ »çÀÌÆ®µé:
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1295
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0963
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0294
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-0480
http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2001-1131

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/windowsntfocus/5SP0M0055W.html
http://www.securiteam.com/windowsntfocus/6W00G206AM.html
http://www.der-keiler.de/Mailing-Lists/Securiteam/2001-08/0083.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
FTP ¸ðµç ¹öÀü
Microsoft Windows Any version
Linux Any version
Unix Any version
ÇØ°áÃ¥ ÆÐÄ¡³ª ¾÷±×·¹À̵带 À§ÇØ Á¦Á¶»ç¿¡ ¹®ÀÇÇØ º»´Ù. ¸¸¾à ÀÌ Ãë¾àÁ¡À» À§ÇÑ ÆÐÄ¡³ª ¾÷±×·¹À̵尡 Á¸ÀçÇÏÁö ¾ÊÀ¸¸é ´Ù¸¥ FTP ¼­¹ö¸¦ »ç¿ëÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)