|
커피향이 나는 *NIX
커피닉스
시스템/네트웍/보안을 다루는 곳
|
|
|
|
| 이전 주제 보기 :: 다음 주제 보기 |
| 글쓴이 |
메시지 |
truefeel 카페 관리자
가입: 2003년 7월 24일 올린 글: 1277 위치: 대한민국
|
올려짐: 2010.12.07 화, 6:13 pm 주제: proftpd 공식 사이트 해킹당해 |
|
|
proftpd 공식 사이트가 해킹을당해서 1.3.3c 버전에 백도어가 심어진채 배포되었었다.
11.28~12.02 사이에 proftpd 소스를 받으신 분들은 백도어가 포함되어 있으니 무조건 새로 받아 MD5를 확인하고 재설치해야한다.
다음은 proftpd 메일링 내용의 일부이다. ([Proftpd-user] ProFTPD ftp.proftpd.org compromise)
| 인용: |
On Sunday, the 28th of November 2010 around 20:00 UTC the main
distribution server of the ProFTPD project was compromised. The
attackers most likely used an unpatched security issue in the FTP daemon
to gain access to the server and used their privileges to replace the
source files for ProFTPD 1.3.3c with a version which contained a backdoor.
The fact that the server acted as the main FTP site for the ProFTPD
project (ftp.proftpd.org) as well as the rsync distribution server
(rsync.proftpd.org) for all ProFTPD mirror servers means that anyone who
downloaded ProFTPD 1.3.3c from one of the official mirrors from 2010-11-28
to 2010-12-02 will most likely be affected by the problem.
|
소스별 MD5값이다. 배포되는 소스의 MD5값은 http://www.proftpd.org/md5_pgp.html 에서 알 수 있다.
리눅스는 'md5sum <소스 파일명>'으로
FreeBSD는 'md5 <소스 파일명>'으로 MD5값이 맞는지 확인할 수 있다.
| 코드: |
018e0eb1757d9cea2a0e17f2c9b1ca2d proftpd-1.3.2e.tar.bz2
4ecb82cb1050c0e897d5343f6d2cc1ed proftpd-1.3.2e.tar.gz
8571bd78874b557e98480ed48e2df1d2 proftpd-1.3.3c.tar.bz2
4f2c554d6273b8145095837913ba9e5d proftpd-1.3.3c.tar.gz
|
다음은 메일링리스트 등 관련글이다.
- [Proftpd-user] ProFTPD ftp_proftpd_org compromise (메일링)
- ProFTPD Backdoor Unauthorized Access Vulnerability
- Open-source ProFTPD hacked, backdoor planted in source code
※ 2010.12.6(월) 커피닉스 방의 '티니(tini)'님 이야기를 토대로 정리 |
|
| 위로 |
|
 |
|
|
새로운 주제를 올릴 수 있습니다 답글을 올릴 수 있습니다 주제를 수정할 수 없습니다 올린 글을 삭제할 수 없습니다 투표를 할 수 없습니다
|
Powered by phpBB © 2001, 2005 phpBB Group
|