Ãë¾àÁ¡ID |
16041 |
À§Çèµµ |
20 |
Æ÷Æ® |
21 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
FTP |
»ó¼¼¼³¸í |
ProFTPd µ¥¸óÀÌ Á¶ÀÛµÈ 'ls' ¸í·ÉÀ» ÅëÇÑ ¼ºñ½º °ÅºÎ(Denial of Service) °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ÇöÀç ¸¹Àº Ãë¾àÁ¡µéÀÌ FTP ¼ºñ½º¿¡ ±¸ÇöµÈ glob() ¾Ë°í¸®Áò »óÀÇ ¹ö±×·Î ÀÎÇÏ¿© ¹ß»ýÇÑ´Ù. ±× Áß¿¡¼ ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁö °ø°ÝÀÚ°¡ µð·ºÅ丮 ¸®½ºÆÃÀ» À§ÇÑ 'ls' ¸í·É¾î ´ÙÀ½¿¡ (*/../*/) ¶Ç´Â (.*./*?/) ¿Í °°Àº Á¶ÀÛµÈ 'dot dot' ½ÃÄö½º(sequence)¸¦ µ¡ºÙ¿© Àü´ÞÇÒ ¶§ ¹ß»ýÇÏ°Ô µÈ´Ù. ÀÌ·¯ÇÑ ¸í·ÉÀ» ¹Þ´Â ¼¹ö´Â ¼¹öÀÇ CPU¿Í ¸ðµç °¡¿ëÇÑ ¸Þ¸ð¸®(memory) ÀÚ¿øÀ» ¼ÒºñÇϱ⠽ÃÀÛÇÑ´Ù. ¸¸¾à, ÀÌ·¯ÇÑ Á¢¼ÓÀÌ µ¿½Ã¿¡ ´Ù¼ö¿¡ ÀÇÇØ¼ ÀÌ·ç¾îÁø´Ù¸é, ¼¹ö »óÀÇ ¸ðµç CPU ¿Í ¸Þ¸ð¸® ÀÚ¿øÀÌ 100% ¼Ò¸ðµÇ¾î ¼¹ö(FTP µ¥¸ó)°¡ Å©·¡½¬(crash) µÉ ¼ö ÀÖ´Ù.
´ÙÀ½°ú °°Àº ¸í·ÉµéÀ» º¸³¿À¸·Î½á ÀÌ Ãë¾àÁ¡À» Á÷Á¢ Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù:
ls */../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../*/../* ls */.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/*/.*/ ls .*./*?/.*./*?/.*./*?/.*./*?/.*./*?/.*./*?/.*./*?/.*./*?/.*./*?/
* ¿µÇâ¹Þ´Â Ç÷§Æûµé: ProFTPD ¹öÀü 1.2.1 °ú ±× ÀÌÇÏ ¹öÀüµé |
ÇØ°áÃ¥ |
ProFTPD À¥ »çÀÌÆ® http://www.proftpd.org ¸¦ ÂüÁ¶ÇÏ¿© ProFTPD ¹öÀü 1.2.5rc1 ¶Ç´Â ±× ÀÌÈÄ ¹öÀüµé·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÇöÀç °¡Àå ÃֽйöÀüÀÎ ProFTPD 1.2.8rc1ÀÌ 2002³â 12¿ù 28ÀÏ¿¡ ¸±¸®Áî(release) µÇ¾ú´Ù.
Àӽà ¹æÆíÀ¸·Î´Â, ȯ°æ¼³Á¤ ÆÄÀÏ proftpd.conf ÆÄÀÏ¿¡ ´ÙÀ½°ú °°ÀÌ Ãß°¡ÇÑ´Ù. : "DenyFilter /\*/\.\." |
°ü·Ã URL |
CVE-2001-1501 (CVE) |
°ü·Ã URL |
2496,6341 (SecurityFocus) |
°ü·Ã URL |
7818 (ISS) |
|