English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 12012
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç IIS ¼­¹ö´Â ¾ÇÀÇÀûÀÎ HTTP HOST Çʵå·Î ÀÎÇÑ ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù.

ÇÁ·ÐÆ®ÆäÀÌÁö ¼­¹ö È®Àå(FrontPage Server Extensions)Àº À¥ °³¹ßÀÚµéÀÌ À¥ ÄÁÅÙÆ®(Content)¸¦ ¼öÁ¤ ¹× Ãß°¡Çϰí À¥ ¼­¹ö¸¦ °ü¸®Çϱâ À§ÇÑ ±â´ÉÀ» Á¦°øÇÑ´Ù. ÇÁ·ÐÆ®ÆäÀÌÁö ¼­¹ö È®Àå(FrontPage Server Extensions)ÀÇ ÄÄÆ÷³ÍÆ® Áß ÇϳªÀÎ SmartHTML ¹ø¿ª±â, Áï, 'shtml.dll'Àº ƯÁ¤ÇÑ Çü½ÄÀÇ µ¿ÀûÀÎ À¥ ÄÁÅÙÆ®(Content)µéÀ» Áö¿øÇÑ´Ù. ÀÌ 'shtml.dll'¿¡´Â À¥ ¼­¹ö°¡ Á¤»óÀûÀ¸·Î µ¿ÀÛÇÒ ¼ö ¾øµµ·Ï ¸¸µå´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
¸¸¾à, ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ´ÙÀ½°ú °°ÀÌ HTTP Çì´õÀÇ HOST Çʵ忡 ¸¹Àº '/' ¹®ÀÚ¸¦ ¿­°ÅÇÑ POST ¿äûÀ» shtml.dll (SmartHTML Interpreter) ÆÄÀÏ¿¡ Àü´ÞÇÏ°Ô µÇ¸é,

POST /_vti_bin/shtml.dll HTTP/1.1
Host: /////////////[...'/'*32762...]//////////////
Content-length: 1
x

IIS À¥ ¼­¹ö´Â ´ë·« 35ÃÊ Á¤µµ »ç¿ëÇÒ ¼ö ÀÖ´Â CPU ÀÚ¿øÀ» 100% ¼Ò¸ðÇÏ°Ô µÇ°í ÀÌ ½Ã°£ µ¿¾È ´õ ÀÌ»ó ´Ù¸¥ HTTP ¿äû¿¡ ´ëÇØ¼­ ¿Ã¹Ù¸¥ ¼­ºñ½º¸¦ Á¦°øÇÏÁö ¸øÇÏ°Ô µÈ´Ù. ÀÌ´Â À¥ ¼­¹ö°¡ ¼­ºñ½º °ÅºÎ(Denial of Service) »óŰ¡ µÇ°Ô ÇÒ ¼ö ÀÖ´Ù.

* Ãë¾àÇÑ Ç÷§Æû:
Microsoft IIS 5.0
- Windows 2000 Any version
Microsoft IIS 5.1
- Windows XP Any version
ÇØ°áÃ¥ 2012³â 4¿ù ÇöÀç ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ¸íÈ®ÇÑ ÇØ°áÃ¥Àº Á¦½ÃµÇ¾î ÀÖÁö ¾Ê´Ù.
°ü·Ã URL CVE-2002-1908 (CVE)
°ü·Ã URL 5907 (SecurityFocus)
°ü·Ã URL 10370 (ISS)