| Ãë¾àÁ¡ID |
16010 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
21 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
FTP |
| »ó¼¼¼³¸í |
FTP ¼¹ö¿¡ anonymous·Î ·Î±×ÀÎÇÒ ¼ö ÀÖ´Ù. FTP(File Transfer Protocol)´Â ½Ã½ºÅÛ°£ÀÇ filesÀ» Àü´ÞÇϱâ À§ÇÑ ÇÁ·ÎÅäÄÝÀÌ´Ù. FTP ¼ºñ½º´Â µ¥ÀÌÅÍ Åë½Å¿ëÀÇ ¸¹Àº applicationµé¿¡ »ç¿ëµÈ´Ù. ¾î¶² ½Ã½ºÅÛÀº »ç¿ëÀÚ°¡ filesÀ» uploadÇϰųª downloadÇÒ ¼ö ÀÖµµ·Ï FTP ¼¹ö¿¡ ¿¬°á½Ã۱⵵ ÇÑ´Ù. FTP ¼¹ö´Â ÀÎÁõ ¾øÀÌ ÆÄÀϵé(password files Æ÷ÇÔ)À» °Ë»öÇϰųª ±× ¼¹öÀÇ ´Ù¸¥ ºÎºÐ¿¡ ¸í·É¾î¸¦ ½ÇÇà½ÃŰ´Â ±¤¹üÀ§ÇÑ °ø°Ý¿¡ ´ëÇØ Ãë¾àÇÏ´Ù. Anonymous FTP´Â ¼¹ö¿¡ ¿¬°áµÈ ´©±¸µçÁö ±× ¼¹ö¿¡ loginÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. ÀáÀçÀûÀΠħÀÔ ¹× °ø°Ý¹æ¹ýÀº Á¡Á¡ ´õ Áõ°¡Çϰí ÀÖÀ¸¸ç anonymous FTP¿¡ ´ëÇÑ Á¢±Ù ¶ÇÇÑ ¸¹Àº ´Ù¸¥ ¹æ¹ýÀ¸·Î ¿À¿ëµÉ ¼ö ÀÖ´Ù. ¿¹¸¦ µé¾î, anonymous FTP site¸¦ illegal fileµéÀÇ ÁýÇÕÀÎ "drop zone"À¸·Î ÀÌ¿ëÇÒ ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://xforce.iss.net/xforce/xfdb/52
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: FTP ¸ðµç ¹öÀü Microsoft Windows Any version Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
¹Ýµå½Ã ÇÊ¿äÇÏÁö ¾Ê´Ù¸é anonymous FTP Á¢±ÙÀ» Çã¿ëÇÏÁö ¾Ê´Â´Ù. ¶ÇÇÑ FTP Á¢±Ù ¹× Àü¼Û¿¡ °üÇÑ ¸ðµç »çÇ׿¡ ´ëÇØ ·Î±×(log)¸¦ ¸¸µéµµ·Ï ½Ã½ºÅÛÀ» ±¸¼ºÇϰí ÁÖ±âÀûÀ¸·Î ±× log¸¦ È®ÀÎÇÏ¿© ¿À¿ë ¹× ³²¿ëÀÇ ÆÐÅÏÀ» ã´Â´Ù. FTP ¼¹öÀÇ home directory°¡ writableÇÏÁö ¾Ê°í ½Ã½ºÅÛ IDs(root ¹× uucp, nobody, binÀ» Æ÷ÇÔ)·ÎºÎÅÍÀÇ Á¢±ÙÀ» Çã¿ëÇÏÁö ¾Êµµ·Ï ÇÑ´Ù. °¡´ÉÇÏ´Ù¸é firewall¿¡¼´Â FTP ¼ºñ½º¸¦ Åë°úÇÏÁö ¸øÇÏ°Ô Filtering ½ÃŲ´Ù. |
| °ü·Ã URL |
CVE-1999-0497 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|