È£½ºÆÃ È£½ºÆÃ µµ¸ÞÀÎ ¸¶ÀÌÆäÀÌÁö °í°´¼¾ÅÍ

È£½ºÆÃ ¼¾ÅÍ Å¸ÀÌÆ²
°ßÀû¿äû
È£½ºÆÃ¿¬Àå µµ¸ÞÀο¬Àå È£½ºÆÃ¿¬Àå µµ¸ÞÀο¬Àå
ÅëÇÕÀ¥FTPÁ¢¼Ó
  • ³×ÀÓ¼­¹ö
  • 1Â÷
    hns1.nsgodo.com
    IP: 180.210.127.112
  • 2Â÷
    hns2.nsgodo.com
    IP: 211.233.51.3
°í°´¼¾ÅÍ Àå¾Ö½Å°í
¾È³çÇϼ¼¿ä. nhngodo ÀÔ´Ï´Ù. Á¤ºÎ¿¡¼­ 2020³â±îÁö °ø°øºÐ¾ß ¹× ¹Î°£À¥»çÀÌÆ® ¾×Ƽºêx ÆóÁö ¹× °³¼± ±Ç°í¾È³»·Î ÀÎÇØ ¾×ƼºêX·Î ±¸ÇöµÇ¾î Àִ ȣ½ºÆÃ¿ë °íµµ ÅëÇÕ À¥ FTP Á¦°øÀ» 2019³â¿¡ Á¾·á ¿¹Á¤¿¡ ÀÖ½À´Ï´Ù. ÃßÈÄ ´õ ÁÁÀº ¼­ºñ½º·Î Á¦°ø ¿¹Á¤ÀÌ¿À´Ï ¸¹Àº ¾çÇØ ºÎŹ µå¸®¸ç, ÀÌ¿¡ µû¶ó ÇØ´ç °íµµ FTP ´ë½Å ¾Æ·¡ ¸µÅ©¸¦ ÅëÇÏ¿© FTP ÇÁ·Î±×·¥À» ¼³Ä¡ÇÏ¿© »ç¿ëÇϽñ⸦ ±ÇÀåÇØµå¸³´Ï´Ù. ¾×ƼºêX¶õ? Internet Explore »ç¿ëÀÚ°¡ À¥¼­ºñ½º¸¦ ÀÌ¿ëÇϴµ¥ ÇÊ¿äÇÑ ÀÀ¿ë ÇÁ·Î±×·¥À» ÄÄÇ»ÅÍ¿¡ ÀÚµ¿À¸·Î ¼³Ä¡ÇØÁÖ´Â ±â¼ú·Î ÄÄÇ»ÅÍÀÇ º¸¾ÈÀ» ÀϽÃÀûÀ¸·Î ÇØÁ¦ÇÏ´Â ±â´ÉÀÌ ÀÖ¾î º¸¾È¿¡ Ãë¾àÇÏ¿© Á¤ºÎ¿¡¼­µµ ¾×Ƽºê X¸¦ ÆóÁöÇ϶ó°í ±Ç°íÇϰí ÀÖ½À´Ï´Ù.
FTP ÇÁ·Î±×·¥ (¹«·áÇü ÇÁ·Î±×·¥) ´Ù¿î·Îµå ¹Ù·Î°¡±â
  • FileZilla ´Ù¿î·Îµå
  • FileZilla ¸Å´º¾ó ´Ù¿î·Îµå
´Ý±â
Á¦¸ñ [°øÁö] React, Next.js 'React2Shell' º¸¾È Ãë¾àÁ¡¿¡ µû¸¥ ¾÷µ¥ÀÌÆ® ±Ç°í Á¶È¸¼ö 49°Ç
¾È³çÇϼ¼¿ä, ¿£¿¡ÀÌÄ¡¿£È£½ºÆÃÀÔ´Ï´Ù.

ÃÖ±Ù °ø°³µÈ ¡®React2Shell' ¿ø°Ý ÄÚµå ½ÇÇà(RCE) Ãë¾àÁ¡ÀÌ React ¹× Next.js ÇÁ·ÎÁ§Æ®¿¡¼­ »ç¿ëµÇ´Â React Server
Components(RSC) ±â´É¿¡¼­ ¹ß°ßµÇ¾ú½À´Ï´Ù.
ÇØ´ç Ãë¾àÁ¡Àº °ø°ÝÀÚ°¡ ¿ø°Ý¿¡¼­ ÀÓÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Â Ä¡¸íÀûÀÎ ¼öÁØÀ̸ç, »ç¿ë ÁßÀÎ ÆÐŰÁö ¹öÀüÀ» Áï½Ã È®ÀÎ ÈÄ º¸
¾È¾÷µ¥ÀÌÆ®¸¦ ÁøÇàÇÏ½Ç °ÍÀ» ±Ç°íµå¸³´Ï´Ù.
¾Æ·¡ ³»¿ëÀ» È®ÀÎÇÏ½Ã¾î º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ÁøÇàÇØ ÁÖ¼¼¿ä.

ÀÚ¼¼ÇÑ »çÇ×Àº ¾Æ·¡ ³»¿ëÀ» Âü°í ºÎʵ右´Ï´Ù.

¡á Ãë¾àÁ¡ °ü·Ã Á¤º¸
-  CVE ½Äº°ÀÚ : 
        CVE-2025-55182
        CVE-2025-66478
-  ¸íĪ: ¿ø°Ý ÄÚµå ½ÇÇà(RCE) Ãë¾àÁ¡
-  ¼³¸í
       React Server Components(RSC) ±â´É¿¡¼­ »ç¿ëÇÏ´Â Flight ÇÁ·ÎÅäÄÝÀÇ ¿ªÁ÷·ÄÈ­ ó¸® ·ÎÁ÷ÀÇ °áÇÔÀ¸·Î ÀÎÇØ
       °ø°ÝÀÚ°¡ ¿ø°Ý ÄÚµå ½ÇÇà °ø°Ý ¼öÇà °¡´É
-  µî±Þ
       NIST: ¾ÆÁ÷ ¹Ìµî·Ï
       CNA: Critical(10.0)
-  PoC »óÅÂ: °ø°³

¡á ¿µÇâ ¹Þ´Â ¹öÀü
-  React: 19.0.0, 19.1.0, 19.1.1, 19.2.0
-  Next.js(AppRouter ±â¹Ý): 14.3.0-canary, 15.x, 16.x

¾÷µ¥ÀÌÆ®°¡ Æ÷ÇÔµÈ ¾ÈÀüÇÑ ¹öÀü
React: 19.0.0, 19.1.0, 19.1.1, 19.2,0
Next.js: 14.3.0-canary.88, 15.0.5, 15.1.9, 15.2.6, 15.3.6, 15.4.8, 15.5.7, 16.0.7

¡á Âü°í »çÀÌÆ®
https://nvd.nist.gov/vuln/detail/CVE-2025-55182
https://nvd.nist.gov/vuln/detail/CVE-2025-66478
http://www.openwall.com/lists/oss-security/2025/12/03/4
https://news.ycombinator.com/item?id=46136026
https://react.dev/blog/2025/12/03/critical-security-vulnerability-in-react-server-components
https://www.facebook.com/security/advisories/cve-2025-55182
https://www.wiz.io/blog/critical-vulnerability-in-react-cve-2025-55182
https://vercel.com/changelog/cve-2025-55182
https://cloud.google.com/blog/products/identity-security/responding-to-cve-2025-55182?hl=en

°¨»çÇÕ´Ï´Ù.