English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 16010
À§Çèµµ 20
Æ÷Æ® 21
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FTP
»ó¼¼¼³¸í FTP ¼­¹ö¿¡ anonymous·Î ·Î±×ÀÎÇÒ ¼ö ÀÖ´Ù. FTP(File Transfer Protocol)´Â ½Ã½ºÅÛ°£ÀÇ filesÀ» Àü´ÞÇϱâ À§ÇÑ ÇÁ·ÎÅäÄÝÀÌ´Ù. FTP ¼­ºñ½º´Â µ¥ÀÌÅÍ Åë½Å¿ëÀÇ ¸¹Àº applicationµé¿¡ »ç¿ëµÈ´Ù. ¾î¶² ½Ã½ºÅÛÀº »ç¿ëÀÚ°¡ filesÀ» uploadÇϰųª downloadÇÒ ¼ö ÀÖµµ·Ï FTP ¼­¹ö¿¡ ¿¬°á½Ã۱⵵ ÇÑ´Ù. FTP ¼­¹ö´Â ÀÎÁõ ¾øÀÌ ÆÄÀϵé(password files Æ÷ÇÔ)À» °Ë»öÇϰųª ±× ¼­¹öÀÇ ´Ù¸¥ ºÎºÐ¿¡ ¸í·É¾î¸¦ ½ÇÇà½ÃŰ´Â ±¤¹üÀ§ÇÑ °ø°Ý¿¡ ´ëÇØ Ãë¾àÇÏ´Ù. Anonymous FTP´Â ¼­¹ö¿¡ ¿¬°áµÈ ´©±¸µçÁö ±× ¼­¹ö¿¡ loginÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. ÀáÀçÀûÀΠħÀÔ ¹× °ø°Ý¹æ¹ýÀº Á¡Á¡ ´õ Áõ°¡Çϰí ÀÖÀ¸¸ç anonymous FTP¿¡ ´ëÇÑ Á¢±Ù ¶ÇÇÑ ¸¹Àº ´Ù¸¥ ¹æ¹ýÀ¸·Î ¿À¿ëµÉ ¼ö ÀÖ´Ù. ¿¹¸¦ µé¾î, anonymous FTP site¸¦ illegal fileµéÀÇ ÁýÇÕÀÎ "drop zone"À¸·Î ÀÌ¿ëÇÒ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://xforce.iss.net/xforce/xfdb/52

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
FTP ¸ðµç ¹öÀü
Microsoft Windows Any version
Linux Any version
Unix Any version
ÇØ°áÃ¥ ¹Ýµå½Ã ÇÊ¿äÇÏÁö ¾Ê´Ù¸é anonymous FTP Á¢±ÙÀ» Çã¿ëÇÏÁö ¾Ê´Â´Ù. ¶ÇÇÑ FTP Á¢±Ù ¹× Àü¼Û¿¡ °üÇÑ ¸ðµç »çÇ׿¡ ´ëÇØ ·Î±×(log)¸¦ ¸¸µéµµ·Ï ½Ã½ºÅÛÀ» ±¸¼ºÇϰí ÁÖ±âÀûÀ¸·Î ±× log¸¦ È®ÀÎÇÏ¿© ¿À¿ë ¹× ³²¿ëÀÇ ÆÐÅÏÀ» ã´Â´Ù. FTP ¼­¹öÀÇ home directory°¡ writableÇÏÁö ¾Ê°í ½Ã½ºÅÛ IDs(root ¹× uucp, nobody, binÀ» Æ÷ÇÔ)·ÎºÎÅÍÀÇ Á¢±ÙÀ» Çã¿ëÇÏÁö ¾Êµµ·Ï ÇÑ´Ù. °¡´ÉÇÏ´Ù¸é firewall¿¡¼­´Â FTP ¼­ºñ½º¸¦ Åë°úÇÏÁö ¸øÇÏ°Ô Filtering ½ÃŲ´Ù.
°ü·Ã URL CVE-1999-0497 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)