| Ãë¾àÁ¡ID |
18040 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
25 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
SMTP |
| »ó¼¼¼³¸í |
ÇØ´ç SMTP µ¥¸óÀº RCPT ¸í·ÉÀ» ÅëÇØ E-Mail ÁÖ¼Ò°¡ Ÿ´çÇÑ ÁÖ¼ÒÀÎÁö¸¦ È®ÀÎÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. SMTP ¼¹ö¿¡ ÀÖ´Â RCPT ¸í·ÉÀÌ »ó´ç¼öÀÇ SMTP ±¸Çöµé¿¡ ¹®Á¦°¡ ÀÖ¾î ÀÌ ¸í·ÉÀ» ÅëÇØ Á¦½ÃÇÑ ÁÖ¼Ò°¡ Ÿ´çÇÑ Áö¸¦ ¾Ë¾Æº¸´Âµ¥ »ç¿ëµÉ ¼ö ÀÖ´Ù. VRFY¿Í EXPN ¸í·ÉµéÀÇ ÀÛµ¿ÁßÁö°¡ Á¤º¸¼öÁý °ø°ÝµéÀ» ÀúÁöÇÔ¿¡ ÀÖ¾î ÃæºÐÇÑ °ÍÀ¸·Î ÀÎ½ÄµÇ¾î ¿Ô´Ù. ÇÏÁö¸¸ ÀÌ ¹æ¹ýÀ» ÀÌ¿ëÇÏ¸é »çÀü(dictionary)À» µ¿¿øÇÏ¿© ¸ñÇ¥ SMTP ¼¹ö»óÀÇ »ç¿ëÀÚ ¸®½ºÆ®¸¦ ¾î´À Á¤µµ ÆÄ¾ÇÇØ³¾ ¼ö ÀÖ´Ù. ÀÌ ¸®½ºÆ®´Â ÃßÈÄ SPAM ¸ÞÀÏ °ø°ÝÀÇ ´ë»óÀ¸·Î »ç¿ëµÉ ¼ö ÀÖ´Ù. SMTP ¼¹ö°¡ Ãë¾àÇÑÁö ±×·¸Áö ¾ÊÀºÁö´Â ´ÙÀ½°ú °°ÀÌ Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù:
MAIL FROM: <iamaboy@my.com>
±×¸®°í ³ª¼, RCPT TO ¸í·ÉÀ» ¼öÇàÇÑ´Ù: RCPT TO: <testuser>
¸¸¾à testuser°¡ ¸ñÇ¥ SMTP ¼¹ö¿¡ Á¸ÀçÇÑ´Ù¸é ´ÙÀ½°ú °°Àº ÀÀ´äÀ» ¹Þ´Â´Ù: 250 <testuser>¡¦ Sender ok
¸¸¾à Á¸ÀçÇÏÁö ¾Ê´Â´Ù¸é ´ÙÀ½°ú °°Àº ÀÀ´äÀ» ¹Þ´Â´Ù: 550 <testuser>... User unknown
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/1928.php http://www.securiteam.com/securitynews/2QUPQRPQKA.html |
| ÇØ°áÃ¥ |
¾ÆÁ÷ ÀÌ ±â¹ý¿¡ ´ëÇÑ È¿°úÀûÀÎ ´ë󹿹ýÀº °³¹ßµÇ¾î ÀÖÁö ¾Ê´Ù. µû¶ó¼ ¸ÞÀÏ °ü¸®ÀÚ´Â ¸ÞÀÏ ¼¹öÀÇ ·Î±× ÆÄÀϵ鿡 Á» ´õ °ü½ÉÀ» °¡Á®¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0531 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|