ProFTPDí§Òâ¶ÁÈ¡ºÍдÈëÎļþÎó²îÇ徲ͨ¸æ

Ðû²¼Ê±¼ä 2019-07-23

Îó²î±àºÅºÍ¼¶±ð


CVE±àºÅ£ºCVE-2019-12815£¬ £¬£¬£¬£¬£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬ £¬£¬£¬£¬£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨


Ó°Ïì°æ±¾


ÊÜÓ°ÏìµÄ°æ±¾


ProFTPD 1.3.5b¼°Ö®Ç°°æ±¾


Îó²î¸ÅÊö


ProFTPDÊÇProFTPDÍŶӵÄÒ»Ì×Çå¾²ÔÆ´òÓ¡½â¾ö¼Æ»®¡£¡£¡£¡£¡£¡£¡£¸Ã¼Æ»®Ö§³Ö´ÓÌõ¼Ç±¾µçÄÔ¡¢Ì¨Ê½»úºÍÒÆ¶¯×°±¸ÅþÁ¬´òÓ¡»ú¾ÙÐдòÓ¡¡£¡£¡£¡£¡£¡£¡£


ProFTPD±£´æí§Òâ¶ÁÈ¡ºÍдÈëÎļþÎó²î¡£¡£¡£¡£¡£¡£¡£Ô¶³Ì¹¥»÷Õß¿ÉʹÓøÃÎó²îδ¾­Éí·ÝÑéÖ¤±ã¿ÉÖ´ÐдúÂ벢й¶ÐÅÏ¢¡£¡£¡£¡£¡£¡£¡£


Îó²î·ºÆðÔÚmod_copyÄ£¿£¿£¿£¿£¿éÖУ¬ £¬£¬£¬£¬£¬ËüÊÇÔÚProFTPdµÄĬÈÏ×°ÖÃÖÐÌṩµÄ£¬ £¬£¬£¬£¬£¬²¢ÇÒÔÚ´ó´ó¶¼¿¯Ðа棨ÀýÈçDebian£©ÖÐĬÈÏÆôÓ㬠£¬£¬£¬£¬£¬ÓÉÓÚmod_copyÄ£¿£¿£¿£¿£¿éµÄ×Ô½ç˵CPFRºÍCPTOÏÂÁî²»°´Ô¤ÆÚ¾ÙÐÐÉèÖ㬠£¬£¬£¬£¬£¬µ¼ÖÂÏòProFTPdЧÀÍÆ÷·¢³öCPFR£¬ £¬£¬£¬£¬£¬CPTOÏÂÁîÔÊÐíûÓÐдȨÏÞµÄÓû§¸´ÖÆFTPЧÀÍÆ÷ÉϵÄÈκÎÎļþ¡£¡£¡£¡£¡£¡£¡£


ƾ֤ShodanµÄËÑË÷Ч¹û£¬ £¬£¬£¬£¬£¬ÏÖÔÚÓÐÁè¼ÝÒ»°ÙÍò¸öδÐÞ²¹µÄProFTPdЧÀÍÆ÷¡£¡£¡£¡£¡£¡£¡£


Îó²îÑéÖ¤


ÔÝÎÞPOC/EXP¡£¡£¡£¡£¡£¡£¡£ 


ÐÞ¸´½¨Òé


ÏÖÔÚ³§ÉÌÒÑÐû²¼Éý¼¶²¹¶¡ÒÔÐÞ¸´Îó²î£¬ £¬£¬£¬£¬£¬²¹¶¡»ñÈ¡Á´½Ó£ºhttp://bugs.proftpd.org/show_bug.cgi?id=4372¡£¡£¡£¡£¡£¡£¡£


»º½â²½·¥£º


½ûÓÃProFTPdÉèÖÃÎļþÖеÄmod_copyÄ£¿£¿£¿£¿£¿é¡£¡£¡£¡£¡£¡£¡£


²Î¿¼Á´½Ó


https://www.bleepingcomputer.com/news/security/proftpd-remote-code-execution-bug-exposes-over-1-million-servers/