English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16041
À§Çèµµ 20
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ProFTPd µ¥¸óÀÌ Á¶ÀÛµÈ 'ls' ¸í·ÉÀ» ÅëÇÑ ¼­ºñ½º °ÅºÎ(Denial of Service) °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
ÇöÀç ¸¹Àº Ãë¾àÁ¡µéÀÌ FTP ¼­ºñ½º¿¡ ±¸ÇöµÈ glob() ¾Ë°í¸®Áò »óÀÇ ¹ö±×·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ±× Áß¿¡¼­ ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁö °ø°ÝÀÚ°¡ µð·ºÅ丮 ¸®½ºÆÃÀ» À§ÇÑ 'ls' ¸í·É¾î ´ÙÀ½¿¡ (*/../*/) ¶Ç´Â (.*./*?/) ¿Í °°Àº Á¶ÀÛµÈ 'dot dot' ½ÃÄö½º(sequence)¸¦ µ¡ºÙ¿© Àü´ÞÇÒ ¶§ ¹ß»ýÇÏ°Ô µÈ´Ù. ÀÌ·¯ÇÑ ¸í·ÉÀ» ¹Þ´Â ¼­¹ö´Â ¼­¹öÀÇ CPU¿Í ¸ðµç °¡¿ëÇÑ ¸Þ¸ð¸®(memory) ÀÚ¿øÀ» ¼ÒºñÇϱ⠽ÃÀÛÇÑ´Ù. ¸¸¾à, ÀÌ·¯ÇÑ Á¢¼ÓÀÌ µ¿½Ã¿¡ ´Ù¼ö¿¡ ÀÇÇØ¼­ ÀÌ·ç¾îÁø´Ù¸é, ¼­¹ö »óÀÇ ¸ðµç CPU ¿Í ¸Þ¸ð¸® ÀÚ¿øÀÌ 100% ¼Ò¸ðµÇ¾î ¼­¹ö(FTP µ¥¸ó)°¡ Å©·¡½¬(crash) µÉ ¼ö ÀÖ´Ù.

´ÙÀ½°ú °°Àº ¸í·ÉµéÀ» º¸³¿À¸·Î½á ÀÌ Ãë¾àÁ¡À» Á÷Á¢ Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù:

ls */../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*
ls */.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/
ls .*./*?/.*./*?/.*./*?/.*./*?/.*./*?/.*./*?/.*./*?/.*./*?/.*./*?/

* ¿µÇâ¹Þ´Â Ç÷§Æûµé:
ProFTPD ¹öÀü 1.2.1 °ú ±× ÀÌÇÏ ¹öÀüµé
ÇØ°áÃ¥ ProFTPD À¥ »çÀÌÆ® http://www.proftpd.org ¸¦ ÂüÁ¶ÇÏ¿© ProFTPD ¹öÀü 1.2.5rc1 ¶Ç´Â ±× ÀÌÈÄ ¹öÀüµé·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÇöÀç °¡Àå ÃֽйöÀüÀÎ ProFTPD 1.2.8rc1ÀÌ 2002³â 12¿ù 28ÀÏ¿¡ ¸±¸®Áî(release) µÇ¾ú´Ù.

Àӽà ¹æÆíÀ¸·Î´Â, ȯ°æ¼³Á¤ ÆÄÀÏ proftpd.conf ÆÄÀÏ¿¡ ´ÙÀ½°ú °°ÀÌ Ãß°¡ÇÑ´Ù. :
"DenyFilter /\*/\.\."
°ü·Ã URL CVE-2001-1501 (CVE)
°ü·Ã URL 2496,6341 (SecurityFocus)
°ü·Ã URL 7818 (ISS)