English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16061
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç CesarFTPÀÇ ¹öÀü¿¡ µû¸£¸é FTP ¸í·ÉµéÀ» ÅëÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
CesarFTP´Â Alexandre Cesari¿¡ ÀÇÇØ °³¹ßµÈ ¹«·á Windows FTP ¼­¹öÀÌ´Ù. CesarFTP 0.99g ÀÌÇÏ ¹öÀüµéÀº ¹öÆÛ ¿À¹öÇÃ·Î¿ì °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÔ·Â ¹öÆÛÀÇ ÃÖ´ë ±æÀ̸¦ ÃʰúÇϵµ·Ï °í¾ÈÇÏ¿© ÀûÀýÈ÷ ±¸Á¶È­µÈ Àμö¸¦ ¹®Á¦°¡ µÇ´Â ¸í·É¾î¿¡ ÁÙ ¼ö ÀÖ´Ù. ÀÌ´Â °ø°ÝÀÚ°¡ ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½ÃŰ°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Ãë¾àÇÑ ¸í·ÉµéÀº HELP, USER, PASS, PORT, DELE, REST, RMD, ±×¸®°í MKD°¡ ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°Ë Ç׸ñÀº CesarFTPÀÇ ¹öÀü Á¤º¸¿¡ ÀÇÁ¸ÇÏ¿© Ãë¾àÁ¡À» Á¡°ËÇÑ´Ù. µû¶ó¼­, °ÅÁþ ¾ç¼º ¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2001-07/0001.html
http://archives.neohapsis.com/archives/bugtraq/2001-07/0070.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CesarFTP 0.99g ÀÌÇÏ
Windows Any version
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç·Î½á´Â ¾÷±×·¹À̵峪 ÆÐÄ¡°¡ ³ª¿ÍÀÖÁö ¾Ê´Ù. ÀÌ ÆÐŰÁö¸¦ Á¦°ÅÇÏ°í ´Ù¸¥ ¼Ö·ç¼ÇÀ̳ª ÆÐŰÁö¸¦ »ç¿ëÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.
°ü·Ã URL CVE-2001-0826 (CVE)
°ü·Ã URL 7950,7946 (SecurityFocus)
°ü·Ã URL 6768 (ISS)