English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16051
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç PlatinumFTP ¼­¹ö¿¡´Â dot dot(..) ½ÃÄö½º·Î ÀÎÇÑ ´Ù¼öÀÇ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
PlatinumFTP ¼­¹ö´Â windows 98/NT/ME/2000/XP¿¡¼­ µ¿ÀÛÇϵµ·Ï BYTE/400 »ç¿¡ ÀÇÇØ¼­ Á¦ÀÛµÈ FTP ¼­¹ö ¿£ÁøÀ¸·Î IP ¿¬°á »ó¿¡¼­ ÆÄÀÏ ±³È¯À» À§ÇÑ °£ÆíÇÑ »ç¿ëÀÚ ÀÎÅÍÆäÀ̽º¸¦ Á¦°øÇÑ´Ù. ÀÌ ¼­¹ö¿¡´Â "dot dot(..)" ¸¦ ¿Ã¹Ù¸£°Ô ÇÊÅ͸µ(filtering)ÇÏÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© ´ÙÀ½°ú °°Àº ´Ù¼öÀÇ Ãë¾àÁ¡µéÀÌ Á¸ÀçÇÑ´Ù. ÀÌ·¯ÇÑ Ãë¾àÁ¡µéÀ» ÅëÇÑ °ø°ÝÀÌ ¼º°øÇÏ·Á¸é ÇØ´ç FTP ¼­¹ö¿¡ ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â Àΰ¡µÈ »ç¿ëÀÚ³ª À͸í(anonymous)ÀÇ »ç¿ëÀÚ °èÁ¤ÀÌ ÇÊ¿äÇÏ´Ù.

1. "dot dot(..)" µð·ºÅ丮 Ž»ö Ãë¾àÁ¡(¹öÀü V1.0.6¿Í V1.0.7 Ãë¾àÇÔ):
ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁö °ø°ÝÀÚ°¡ (../) ¶Ç´Â (\..)·Î ±¸¼ºµÈ "dot dot" ½ÃÄö½º(sequence)¸¦ 'DIR' ¸í·É ´ÙÀ½¿¡ µ¡ºÙ¿© ¼­¹ö¿¡ Àü´ÞÇÒ ¶§ ¹ß»ýÇÑ´Ù. ÀÌ·Î ÀÎÇÏ¿© °ø°ÝÀÚ´Â Á¢±Ù±ÇÇÑÀÌ Á¦ÇÑµÈ µð·ºÅ丮 ¿ÜºÎÀÇ ÀÓÀÇÀÇ µð·ºÅ丮¸¦ Ž»öÇÒ ¼ö ÀÖ´Ù.

DIR(LIST) ../../../../ (¶Ç´Â ..\..\..\..\)

2. µ¥ÀÌÅÍ »èÁ¦ Ãë¾àÁ¡(¹öÀü V1.0.6 Ãë¾àÇÔ) :
ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁö °ø°ÝÀÚ°¡ µð·ºÅ丮 Ž»ö ½ÃÄö½º(sequence)¸¦ ÀÌ¿ëÇØ¼­ Á¶ÀÛµÈ 'DELETE' ¸í·ÉÀ» ¼­¹ö¿¡ Àü´ÞÇÒ ¶§ ¹ß»ýÇÑ´Ù. ÀÌ·Î ÀÎÇÏ¿© °ø°ÝÀÚ´Â ¼­¹ö »óÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» »èÁ¦ÇÒ ¼ö ÀÖÀ¸¹Ç·Î ÆÄÀÏ ½Ã½ºÅÛÀÌ ÆÄ±«µÉ À§Ç輺ÀÌ ÀÖ´Ù.

DELETE(DELE) ..\..\..\..\boot.ini

3. ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡(¹öÀü V1.0.6 °ú V1.0.7 Ãë¾àÇÔ) :
ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁö °ø°ÝÀÚ°¡ "@/.." ¸¦ »ç¿ëÇÏ¿© Á¶ÀÛµÈ 'CD' ¸í·ÉÀ» ¼­¹ö¿¡ Àü´ÞÇÒ ¶§ ¹ß»ýÇÑ´Ù. ÀÌ·Î ÀÎÇÏ¿© ¼­¹ö´Â CPU ŸÀÓ(time)À» 99% ¼Ò¸ðÇÏ°Ô µÇ¾î ¼­ºñ½º °ÅºÎ »óÅ¿¡ À̸£°Ô µÈ´Ù.

CD(CWD) @/..@/..

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç FTP ¼­¹öÀÇ ¹è³Ê Á¤º¸¸¦ ÂüÁ¶ÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼öµµ ÀÖ´Ù. ¸¸¾à ¼­ºñ½º°ÅºÎ °ø°Ý¿¡ ÀÇÇÑ ½ÇÁ¦ Å×½ºÆ®¸¦ ¿øÇÑ´Ù¸é, Á¤Ã¥ÆíÁý±â¿¡¼­ "Denial of Service Attacks"¿¡ ÀÖ´Â "ftp/platinumftp/cd_cmd/dos" Ç׸ñÀ» Enable ½ÃŲ ÈÄ Á¡°ËÀ» ÇÏ¸é µÈ´Ù.

* °³º° Ãë¾àÁ¡À» À§ÇÑ Âü°í »çÀÌÆ® :
http://online.securityfocus.com/bid/6492
http://online.securityfocus.com/bid/6493
http://online.securityfocus.com/bid/6494
http://www.iss.net/security_center/static/10953.php
http://www.iss.net/security_center/static/10954.php
http://www.iss.net/security_center/static/10955.php
http://archives.neohapsis.com/archives/bugtraq/2002-12/att-0268/02-advisory.txt

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ PlatinumFTPserver À¥ »çÀÌÆ® http://www.softsea.com/review/PlatinumFTPserver.html ¸¦ ÂüÁ¶ÇÏ¿© PlatinumFTPserver 1.0.8 ¶Ç´Â ±× ÀÌÈÄ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)