| Ãë¾àÁ¡ID |
16071 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
21 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
FTP |
| »ó¼¼¼³¸í |
ÇØ´ç WS FTP ¼¹ö ¹öÀü¿¡ µû¸£¸é, WS FTP ¼¹ö¿¡´Â FTP Bounce Ãë¾àÁ¡°ú PASV mode session hijacking Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Ipswitch »ç¿¡¼ °³¹ßÇÑ WS FTP´Â Microsoft Windows Ç÷§Æû »ó¿¡¼ »ç¿ë °¡´ÉÇÑ FTP ¼¹öÀÌ´Ù. WS FTP 3.13 ¿Í ±× ÀÌÀü ¹öÀüµéÀº ´ÙÀ½ µÎ °¡Áö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù:
- PASV mode session hijacking Ãë¾àÁ¡: FTP »ç¿ëÀÚ°¡ PASV ¿¬°áÀ» ½ÃµµÇÒ ¶§, °ø°ÝÀÚµéÀº ¼¼¼Ç hijackingÀ» À§ÇØ °°Àº Æ÷Æ®¿¡ ¿¬°áÀ» ½ÃµµÇÒ ¼ö ÀÖÀ¸¸ç À̸¦ ÅëÇØ Áß¿äÇÑ Á¤º¸¸¦ ȹµæÇÒ ¼ö ÀÖ´Ù. - FTP Bounce Ãë¾àÁ¡: ¿ø°ÝÁö °ø°ÝÀÚµéÀº Àß Á¶ÀÛµÈ FTP PORT ¸í·ÉÀ» ÀÌ¿ëÇÏ¿©, FTP bounce °ø°ÝÀ» ½ÃµµÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ¿ø°ÝÁö WS FTP ¹öÀü Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2002-10/0367.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Ipswitch, Inc., WS_FTP Server 3.13 ÀÌÇÏ ¹öÀüµé Microsoft Windows Any version |
| ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®·Î¸¦ Âü°íÇÏ¿© WS_FTPÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù: http://www.ipswitchft.com/support/wsftpserver/index.aspx |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
6050,6051 (SecurityFocus) |
| °ü·Ã URL |
10493,10494 (ISS) |
|