English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21289
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í Netware 6.0¿¡ ¹èÆ÷µÈ ÇØ´ç Apache Tomcat ¼­¹ö´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Apache TomcatÀº JSP(JavaServer Page)µé°ú Java ¼­ºí¸´(servlet)µéÀ» Áö¿øÇϱâ À§ÇÏ¿© Apache HTTP ¼­¹ö¿Í ÇÔ²² »ç¿ëµÇ´Â Java ¾îÇø®ÄÉÀÌ¼Ç ¼­¹öÀÌ´Ù. Netware 6.0¿¡ ¹èÆ÷µÈ Apache Tomcat ¼­¹ö¿¡ ÀÖ´Â '/examples/jsp/source.jsp' ¿¹Á¦ ½ºÅ©¸³Æ®´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥ ¼­¹ö »ó¿¡ ÀÖ´Â ÀÓÀÇÀÇ ÆÄÀϵéÀÇ ³»¿ëÀ» º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
'source.jsp' ½ºÅ©¸³Æ®´Â '/../' ½ÃÄö½ºµéÀ» ÅëÇÑ µð·ºÅ丮 Ž»öÀ» Â÷´ÜÇÑ´Ù. ±×·¯³ª Unicode ¹®ÀÚµéÀ» °¡Áø '/%2e%2e/' ½ÃÄö½ºµéÀ» ÅëÇÑ µð·ºÅ丮 Ž»öÀ» ½ÃµµÇÏ´Â °ø°ÝÀÚ´Â ¼º°øÇÑ´Ù. ÀÌ´Â °ø°ÝÀÚ°¡ À¥ ¼­¹ö¿¡ ÀÇÇØ ÀÐÀ» ¼ö ÀÖ´Â Ãë¾àÇÑ ½Ã½ºÅÛ »óÀÇ ¾î¶² ÆÄÀϵ鿡 ´ëÇÑ ¿äûÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ Ãë¾àÁ¡À» µµ¿ëÇϱâ À§ÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¾Ë·ÁÁø ÆÄÀÏ¿¡ ´ëÇØ "dot dot" ½ÃÄö½º (/%2e%2e/)¸¦ Æ÷ÇÔÇÑ "source.jsp" ¿äûÀ» º¸³½´Ù. ÀÌ´Â °ø°ÝÀÚ°¡ AUTOEXEC.NCF¿¡ À§Ä¡ÇÑ RCONSOLE ÆÐ½º¿öµå¿Í °°Àº Netware ¼­¹ö¿¡¼­ Áß¿äÇÑ Á¤º¸¸¦ ¾ò¾î ¿Ã ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

http://[targetserver]/examples/jsp/source.jsp?%2e%2e/%2e%2e/%2e%2e/%2e%2e/system/autoexec.ncf

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache Software Foundation Tomcat Any version
Netware 6.0
ÇØ°áÃ¥ ¿µÇâÀ» ¹Þ´Â À¥ ¼­¹ö·ÎºÎÅÍ "/examples/" °¡»ó µð·ºÅ丮¿¡ À§Ä¡ÇØ ÀÖ´Â µðÆúÆ® ¿¹Á¦ ÆÄÀϵéÀ» »èÁ¦ÇÏ¿©¾ß ÇÑ´Ù. ¶ÇÇÑ RCONSOLE ÆÐ½º¿öµå°¡ ¾ÏȣȭµÇ¾î ÀÖ´ÂÁö¿Í ÄÜ¼Ö ¾×¼¼½º ½Ã ÆÐ½º¿öµå·Î º¸È£µÈ È­¸éº¸È£±â¸¦ »ç¿ëÇϰí ÀÖ´ÂÁö¸¦ È®½ÇÈ÷ ÇØ µÎ¾î¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)