English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21234
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç SMB2WWW ´Â ¿ø°ÝÁö °ø°ÝÀڵ鿡 ÀÇÇÑ ÀÓÀÇÀÇ ¸í·É ½ÇÇàÀ» Çã¿ëÇÑ´Ù.
SMB2WWW ´Â À¥ ºê¶ó¿ìÀú¸¦ ÅëÇØ¼­ ¾×¼¼½º °¡´ÉÇÑ Windows ³×Æ®¿öÅ© Ŭ¶óÀÌ¾ðÆ®·Î¼­, »ï¹Ù(Samba), ÆÞ(Perl), ±×¸®°í À¥ ¼­¹ö(web server)°¡ Áö¿øµÇ´Â Solaris ³ª Linux ½Ã½ºÅÛ¿¡¼­ µ¿ÀÛÇÑ´Ù. ÀÌ SMB2WWW ÀÇ ÀϺΠ¹öÀü¿¡´Â ¿ø°ÝÁö °ø°ÝÀڵ鿡 ÀÇÇØ ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ¸í·ÉÀÌ ½ÇÇàµÉ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ Ãë¾àÁ¡Àº ´ÙÀ½°ú °°ÀÌ SMB2WWW ÄÄÆ÷³ÍÆ® Áß ÇϳªÀÎ "smbshr.pl" ¿¡ ¾ÇÀÇÀûÀÎ ÀÎÀÚ(argument)¸¦ º¸³¾ ¶§ ¹ß»ýÇÑ´Ù.

POST /cgi-bin/smbshr.pl HTTP/1.1
Host: X.X.X.X
....
Content-Length: XX

host=%22%20%2DFOOBAR%7Cecho%20%22%20Sharename%22%0Aecho%0Aecho%20%22%20%20SomeShare%20%20Disk%20%22%60id%60%20%23%22

ÀÌ¿Í °°Àº ¿äûÀº °ø°ÝÀÚ°¡ ´ë»ó ½Ã½ºÅÛ »ó¿¡ "www-data" »ç¿ëÀÚ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ÇÁ·Î±×·¥À» ½ÇÇàÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/advisories/4741

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SMB2WWW 980804-16 and prior
Debian Linux 2.2
Debian Linux 3.0
ÇØ°áÃ¥ Áï½Ã °¡Àå ÃÖ½ÅÀÇ SMB2WWW ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.

Debian 2.2 (potato)ÀÇ °æ¿ì:
http://www.debian.org/security/2002/dsa-203

Debian 3.0 (woody)ÀÇ °æ¿ì:
http://www.debian.org/security/2002/dsa-203

´Ù¿î·Îµå°¡ µÇÁö ¾ÊÀ» °æ¿ì º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÃÖ½ÅÀÇ SMB2WWW ÆÐŰÁö·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2002-1342 (CVE)
°ü·Ã URL 6313 (SecurityFocus)
°ü·Ã URL 10768 (ISS)