English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16004
À§Çèµµ 40
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í ÇØ´ç Anonymous FTP ¼­¹ö´Â home µð·ºÅ丮°¡ ¾²±â °¡´ÉÇÏ°Ô µÇ¾î ÀÖ´Ù.
¸¸¾à FTP ¼­¹ö°¡ ÀÎÅͳݿ¡ °ø°³µÈ ¼­¹ö¶ó¸é "warez" ¼­¹ö (Áï, FTP ¼­¹ö°¡ ¼ÒÇÁÆ®¿þ¾î ÇØÀûÆÇÀÌ Åë¿ëµÇ´Â ¸ñÀûÀ¸·Î ´Ù¼öÀÇ »ç¿ëÀڵ鿡 ÀÇÇØ »ç¿ëµÇ´Â °ÍÀ» ÀǹÌ)·Î ´©±º°¡¿¡ ÀÇÇØ »ç¿ëµÉ ¼ö ÀÖ´Ù. ¶ÇÇÑ ´©±º°¡¿¡ ÀÇÇØ FTP ¼­¹öÀÇ ÆÄÀϽýºÅÛÀÌ °¡µæ ä¿öÁ® ¼­ºñ½º °ÅºÎ(denial of service)°¡ ¹ß»ýÇÒ ¼öµµ ÀÖ´Ù.
±×¸®°í ¸¸¾à Anonymous FTP ¼­¹ö°¡ À¯´Ð½º ½Ã½ºÅÛÀ̶ó¸é °ø°ÝÀÚ´Â .rhosts¿Í .forward ÆÄÀϵéÀ» ÀûÀýÇÏ°Ô ¸¸µé¾î ³õ°í r-commandµéÀ̳ª sendmailÀ» ÀÌ¿ëÇÏ¿© ÇØ´ç ftp ¼­¹ö¸¦ ÇØÅ·ÇÒ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/53.php
http://ciac.llnl.gov/ciac/bulletins/d-19.shtml

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Any version
Linux Any version
Unix Any version
FTP ¸ðµç ¹öÀü
ÇØ°áÃ¥ ÇØ´ç FTP ¼­¹öÀÇ È¨ µð·ºÅ丮 Permission ÀûÀýÇÏ°Ô ¼ÂÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-1999-0527 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)