Ãë¾àÁ¡ID |
16037 |
À§Çèµµ |
40 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ÇØ´ç FTP ¼¹ö¿¡ ÀÖ´Â CWD ~root ¸í·ÉÀº root ¾×¼¼½º¸¦ Çã¿ëÇÑ´Ù. FTP µ¥¸óÀÇ ¸Å¿ì ¿À·¡µÈ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ »ç¿ëÀڵ鿡°Ô "CWD ~root" ¸í·ÉÀÇ »ç¿ë¿¡ ÀÇÇÑ Àΰ¡µÇÁö ¾ÊÀº ¾×¼¼½º¸¦ Çã¿ëÇØ ÁÙ ¼ö ÀÖ´Ù. "CWD ~root" ¸í·ÉÀ» Æ÷ÇÔÇÏ´Â ÀÏ·ÃÀÇ ¸í·ÉµéÀ» ÁÜÀ¸·Î½á °ø°ÝÀÚ´Â Ãë¾àÇÑ FTP ¼¹ö»ó¿¡ ÀÎÁõÀ» ¿ìȸÇϰí root ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖÀ¸¸ç À̸¦ ÅëÇØ root ±ÇÇÑÀ» °¡Áö°í FTP Root µð·ºÅ丮 ¿ÜºÎÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù. ±¤¹üÀ§ÇÏ°Ô µµ¿ëµÇ¾î ¿Â ÀÌ Ãë¾àÁ¡À» È®ÀÎÇϱâ À§Çؼ´Â ´ÙÀ½°ú °°ÀÌ ÇÒ ¼ö ÀÖ´Ù:
% ftp -n ftp> open victim.com Connected to victim.com 220 victim.com FTP server ready. Ftp> quote user ftp 331 Guest login ok, send ident as password. Ftp> quote cwd ~root 530 Please login with USER and PASS. Ftp> quote pass ftp@ 230 Guest login ok, access restrictions apply. Ftp> ls -al / (or whatever)
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/54.php http://www.alw.nih.gov/Security/Docs/admin-guide-to-cracking.101.html
* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû: FTP ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
Ãë¾àÇÑ FTP ´ë¸óÀ» ÃÖ½ÅÀÇ FTP ÆÐŰÁö·Î ´ëüÇÏ¿©¾ß ÇÑ´Ù.
¶ÇÇÑ ÀÌ °ø°Ý¿¡ Ãë¾àÇÑ FTP ´ë¸óµéÀº ±¸ ¹öÀüÀÇ ¿î¿µÃ¼Á¦¸¦ °¡Áö°í ÀÖÀ» °ÍÀÌ´Ù. Çϵå¿þ¾î°¡ Áö¿øÇØ ÁÖ´Â ¹üÀ§³»¿¡¼ °¡Àå ÃÖ½ÅÀÇ ¿î¿µÃ¼Á¦·Î ¾÷±×·¹À̵åÇÏ´Â ¹æ¾Èµµ °í·ÁÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-1999-0082 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|