涉及程序: Sun Solaris FTP 描述: Solaris FTP客户端在调试模式下口令在本地屏幕直接显示 详细: Solaris下的FTP客户端在调试模式下运行时存在缺陷,本地攻击者可通过浏览屏幕信息,非法获得用户口令。 当Solaris用户调用\"ftp -d\"命令时,便会启用调式模式。在这种模式下输入的FTP口令字串会直接显示在屏幕上,使用户的这一敏感信息易泄露。 受影响系统: Sun Solaris FTP - Sun Solaris 8.0 x86 - Sun Solaris 8.0 SPARC - Sun Solaris 7.0 SPARC - Sun Solaris 7.0 x86 - Sun Solaris 2.6 SPARC - Sun Solaris 2.6 x86 攻击方法: 当使用\"ftp -d\"的时输入的密码以明文方式显示在屏幕上: % ftp -d localhost Connected to localhost. 220 hostname FTP server (SunOS 5.8) ready. Name (localhost:usera): myusername ---> USER myusername 331 Password required for myusername. Password: ---> PASS my_secret_passwd 230 User myusername logged in. 解决方案: Sun公司已发布安全公告(Sun-Alert-51081)以及相应补丁,建议用户立即下载: http://sunsolve.sun.com/pub-cgi/retrieve.pl?doc=fsalert/51081