CNCVE编号:CNCVE-20020005 CVE编号: 安全级别:高 漏洞中文描述: Ntop是一个Unix平台下的工具程序,用于查看网络的使用情况与Unix下的top命令相似。这个工具也已经被移植到了Windows平台下(使用libpcap for Win33)。Ntop内置了一个Web服务器,可以通过网络使用它。Ntop实现上存在格式化字符串漏洞,远程攻击者可能利用这个漏洞在主机上以root身份执行任意指令。 漏洞英文描述: Ntop is a UNIX tool that shows the network usage, similar to what the popular top UNIX command does on the system level. A format string vulnerability has been discovered on the programmatic level and is currently known to affect the UNIX version, however, the Windows port of the program remains untested. The vulnerability allows for remote arbitrary code execution. 漏洞参考: http://archives.neohapsis.com/archives/bugtraq/2002-03/0023.html http://archives.neohapsis.com/archives/bugtraq/2002-03/0026.html http://www.ntop.org/ntop.html 向服务器程序提交以下的URL会导致ntop程序崩溃: GET /%s%s%s HTTP/1.0 系统类型:其他 漏洞类型:缓冲区溢出