English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12011
À§Çèµµ 20
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç IIS 5.0 ¼­¹ö´Â À߸øµÈ "Content-Length" °ªÀ» ÅëÇÑ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù.

¸¸¾à, ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ´ÙÀ½°ú °°ÀÌ HTTP GET Çì´õ ¾È¿¡ ¿Ã¹Ù¸£Áö ¾ÊÀº Content-Length °ªÀ» ¸í½ÃÇÏ¿© ¼­¹ö¿¡°Ô Àü´ÞÇÏ´Â °æ¿ì,

GET /testfile HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg,
application/vnd.ms-excel, application/vnd.ms-powerpoint,
application/msword, */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
Host: 192.168.0.10
Connection: Keep-Alive
Content-Length: 5300643
Authorization: Basic

IIS À¥¼­¹ö´Â ½Ã°£Ãʰú ¾øÀÌ Á¢¼ÓÀÌ ¿¬°áµÈ »óŸ¦ À¯ÁöÇÑ Ã¤, ¾Æ¹«·± ÀÀ´äµµ ÇÏÁö ¾Ê´Â´Ù. ¸¸¾à À̿Ͱ°ÀÌ Á¢¼ÓÇÑ ¿¬°áµéÀÌ ¸¹¾ÆÁú °æ¿ì ¼­¹ö´Â ´õÀÌ»ó »õ·Î¿î Á¢¼Ó ¿äû¿¡ ´ëÇØ ¼­ºñ½º¸¦ ÇÏÁö ¸øÇÏ°Ô µÈ´Ù. ÀÌ´Â À¥¼­¹ö°¡ ¼­ºñ½º°ÅºÎ »óŰ¡ µÇ°Ô ÇÒ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/7691.php
http://online.securityfocus.com/bid/3667

* Ãë¾àÇÑ Ç÷§Æûµé:
Microsoft IIS 5.0
- Windows 2000 Advanced Server
- Windows 2000 Advanced Server SP1/SP2
- Windows 2000 Datacenter Server SP1/SP2
- Windows 2000 Professional
- Windows 2000 Professional SP1/SP2
- Windows 2000 Server
- Windows 2000 Server SP1/SP2

* Ãë¾àÇÏÁö ¾ÊÀº Ç÷§Æû:
Windows XP, VISTA, 7, 8
Windows Server 2003, 2008, 2012
ÇØ°áÃ¥ 2012³â 4¿ù ÇöÀç ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÇØ°áÃ¥Àº Á¦½ÃµÇ¾î ÀÖÁö ¾Ê´Ù.
°ü·Ã URL CVE-2001-1186 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)