½Ã½ºÅÛ°ü¸®ÀÚÀÇ ½°ÅÍ Ä¿ÇǴнº Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
 FAQFAQ   °Ë»ö°Ë»ö   ¸â¹ö¸®½ºÆ®¸â¹ö¸®½ºÆ®   »ç¿ëÀÚ ±×·ì»ç¿ëÀÚ ±×·ì   »ç¿ëÀÚ µî·ÏÇϱâ»ç¿ëÀÚ µî·ÏÇϱâ 
 °³ÀÎ Á¤º¸°³ÀÎ Á¤º¸   ºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀ   ·Î±×Àηα×ÀΠ

°¡ÀÔ¾øÀÌ ´©±¸³ª ±ÛÀ» ¾µ ¼ö ÀÖ½À´Ï´Ù. °øÁö»çÇ׿¡ ´ëÇÑ ´ñ±Û±îÁöµµ..




BBS >> ¼³Ä¡, ¿î¿µ Q&A | ³×Æ®¿÷, º¸¾È Q&A | ÀÏ¹Ý Q&A || Á¤º¸¸¶´ç | AWS || ÀÚÀ¯°Ô½ÃÆÇ | ±¸Àα¸Á÷ || °øÁö»çÇ× | ÀǰßÁ¦½Ã
IIS 5.0~7.0¿¡¼­ FTPÃë¾àÁ¡ (Ãß°¡ »çÇ×)

 
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â  
±Û¾´ÀÌ ¸Þ½ÃÁö
truefeel
Ä«Æä °ü¸®ÀÚ


°¡ÀÔ: 2003³â 7¿ù 24ÀÏ
¿Ã¸° ±Û: 1277
À§Ä¡: ´ëÇѹα¹

¿Ã¸®±â¿Ã·ÁÁü: 2009.9.04 ±Ý, 2:01 pm    ÁÖÁ¦: IIS 5.0~7.0¿¡¼­ FTPÃë¾àÁ¡ (Ãß°¡ »çÇ×) Àοë°ú ÇÔ²² ´äº¯



Áö³­ 8¿ù¸»¿¡ ³ª¿Ô´ø IIS 5.0°ú 6.0ÀÇ ¹øµé·Î Á¦°øµÇ´Â FTP¿¡¼­ ¿ø°Ý ¸í·É ½ÇÇà Ãë¾àÁ¡ÀÌ Á¸ÀçÇß´Ù. ÀÌ¿¡ ´ëÇØ¼­´Â 'IIS 5.0°ú 6.0ÀÇ FTP Ãë¾àÁ¡'(9¿ù 2ÀÏ)¿¡ Àû¾îµ×´Ù.
±× ÈÄ 9.3(¸ñ)¿¡ IIS 5.0~7.0ÀÇ FTP¿¡¼­ DoSÃë¾àÁ¡ÀÌ Ãß°¡ ¹ßÇ¥µÇ¾ú´Ù.

* Vulnerabilities (plural) in MS IIS FTP Service 5.0, 5.1. 6.0, 7.0, (Fri, Sep 4th)
* Microsoft Security Advisory (975191) (9¿ù3ÀÏ ³»¿ë ¾÷µ¥ÀÌÆ®)

Àοë:

Published: September 01, 2009 | Updated: September 03, 2009
... »ý·« ...
The vulnerabilities could allow remote code execution (RCE) on systems running FTP Service on IIS 5.0, or denial of service (DoS) on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0.


À§ º¸¾È±Ç°í¹®Àº IIS 5.0, 6.0ÀÇ FTPÃë¾àÁ¡ÀÌ ³ª¿Â ÈÄ 9¿ù 1ÀÏ ÀÛ¼ºµÇ¾ú°í,
±× µÚ 9¿ù 3ÀÏ IIS 7.0ÀÇ FTP¿¡¼­ DoSÃë¾àÁ¡À» Ãß°¡ÇÏ¿© ¾÷µ¥ÀÌÆ®ÇÏ¿´´Ù.

- CVE-2009-3023 (RCE on IIS 5.0 and DoS on IIS 5.1 and IIS 6.0)
- CVE-2009-2521 (DoS on IIS 5.0, IIS 5.1, IIS 6.0, and IIS 7.0)


FTP Ãʱâ Ãë¾àÁ¡¿¡ ´ëÇÑ ±Ç°í¹®µéÀÌ´Ù.

- ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® IIS 5/6 FTP ¼­ºñ½º ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡ (9.1, ¾Èö¼ö¿¬±¸¼Ò)
- MS IIS FTP ¼­ºñ½ºÀÇ ¿ø°ÝÄÚµå½ÇÇà Ãë¾àÁ¡ ÁÖÀÇ (9.2, KRCERT)
À§·Î
»ç¿ëÀÚ Á¤º¸ º¸±â ºñ¹Ð ¸Þ½ÃÁö º¸³»±â ±Û ¿Ã¸°ÀÌÀÇ À¥»çÀÌÆ® ¹æ¹®
Á¤¹Î±³
¼Õ´Ô





¿Ã¸®±â¿Ã·ÁÁü: 2009.11.05 ¸ñ, 9:39 pm    ÁÖÁ¦: Re: IIS 5.0~7.0¿¡¼­ FTPÃë¾àÁ¡ (Ãß°¡ »çÇ×) Àοë°ú ÇÔ²² ´äº¯

truefeel ¾¸:


Áö³­ 8¿ù¸»¿¡ ³ª¿Ô´ø IIS 5.0°ú 6.0ÀÇ ¹øµé·Î Á¦°øµÇ´Â FTP¿¡¼­ ¿ø°Ý ¸í·É ½ÇÇà Ãë¾àÁ¡ÀÌ Á¸ÀçÇß´Ù. ÀÌ¿¡ ´ëÇØ¼­´Â 'IIS 5.0°ú 6.0ÀÇ FTP Ãë¾àÁ¡'(9¿ù 2ÀÏ)¿¡ Àû¾îµ×´Ù.
±× ÈÄ 9.3(¸ñ)¿¡ IIS 5.0~7.0ÀÇ FTP¿¡¼­ DoSÃë¾àÁ¡ÀÌ Ãß°¡ ¹ßÇ¥µÇ¾ú´Ù.

* Vulnerabilities (plural) in MS IIS FTP Service 5.0, 5.1. 6.0, 7.0, (Fri, Sep 4th)
* Microsoft Security Advisory (975191) (9¿ù3ÀÏ ³»¿ë ¾÷µ¥ÀÌÆ®)

Àοë:

Published: September 01, 2009 | Updated: September 03, 2009
... »ý·« ...
The vulnerabilities could allow remote code execution (RCE) on systems running FTP Service on IIS 5.0, or denial of service (DoS) on systems running FTP Service on IIS 5.0, IIS 5.1, IIS 6.0 or IIS 7.0.


À§ º¸¾È±Ç°í¹®Àº IIS 5.0, 6.0ÀÇ FTPÃë¾àÁ¡ÀÌ ³ª¿Â ÈÄ 9¿ù 1ÀÏ ÀÛ¼ºµÇ¾ú°í,
±× µÚ 9¿ù 3ÀÏ IIS 7.0ÀÇ FTP¿¡¼­ DoSÃë¾àÁ¡À» Ãß°¡ÇÏ¿© ¾÷µ¥ÀÌÆ®ÇÏ¿´´Ù.

- CVE-2009-3023 (RCE on IIS 5.0 and DoS on IIS 5.1 and IIS 6.0)
- CVE-2009-2521 (DoS on IIS 5.0, IIS 5.1, IIS 6.0, and IIS 7.0)


FTP Ãʱâ Ãë¾àÁ¡¿¡ ´ëÇÑ ±Ç°í¹®µéÀÌ´Ù.

- ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® IIS 5/6 FTP ¼­ºñ½º ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡ (9.1, ¾Èö¼ö¿¬±¸¼Ò)
- MS IIS FTP ¼­ºñ½ºÀÇ ¿ø°ÝÄÚµå½ÇÇà Ãë¾àÁ¡ ÁÖÀÇ (9.2, KRCERT)
Crying or Very sad
À§·Î
ÀÌÀü ±Û Ç¥½Ã:   
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸ ½Ã°£´ë: GMT + 9 ½Ã°£(Çѱ¹)
ÆäÀÌÁö 1 Áß 1

 
°Ç³Ê¶Ù±â:  
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù
¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù
ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù


Powered by phpBB © 2001, 2005 phpBB Group