English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21328
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç RiSearch ¼ÒÇÁÆ®¿þ¾î´Â Open Proxy Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
RiSearch (±×¸®°í Pro) ÆÐŰÁö´Â »ç¿ëÀÚµéÀÌ Microsoft Windows, Unix ±×¸®°í Linux Ç÷§ÆûµéÀ» À§ÇÑ À¥ »çÀÌÆ®µéÀ» °Ë»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â ÇÑ ¼¼Æ®ÀÇ PERL ½ºÅ©¸³Æ®µéÀÌ´Ù. RiSearch ¹öÀü 1.0.1 ÀÌÇÏ ±×¸®°í RiSearch Pro ¹öÀü 3.2.6Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ´ÙÀ½°ú °°Àº ¿äûÀ» ÇÔÀ¸·Î½á RiSearch¸¦ Open Proxy ¼­¹ö·Î »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù:

http://[target.com]/cgi-bin/search/show.pl?url=http://www.google.com

ÀÌ °áÇÔÀº show.pl ½ºÅ©¸³Æ®·ÎÀÇ »ç¿ëÀÚ Á¦°ø URI Àμöµé¿¡ ´ëÇÑ Ã³¸® °úÁ¤¿¡¼­ÀÇ ºÒÃæºÐÇÑ ÇÊÅ͸µ¿¡ ±âÀÎÇÑ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» µµ¿ëÇÏ¿© ´ë»ó È£½ºÆ®¸¦ ÇÁ·Ï½Ã(Proxy)·Î¼­ ÀÌ¿ë, ÀÎÅÍ³Ý »ó¿¡ ÀÖ´Â À¥ ¼­¹öµéÀ» À͸íÀ¸·Î ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â À¥ ÇÁ·ÎÅäÄݵéÀ» ÀÌ¿ëÇÏ¿© ´Ù¸¥ ¼­¹öµéÀ» ºÐ¼®/°ø°ÝÇÏ´Â µ¥¿¡ ¸Å¿ì À¯¿ëÇÏ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/370103

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
S.Tarasov, RiSearch 1.0.1 ÀÌÇÏ
S.Tarasov, RiSearch Pro 3.2.6
Microsoft Windows Any version
Unix Any version
Linux Any version
ÇØ°áÃ¥ RiSearchÀÇ ´Ù¿î·Îµå »çÀÌÆ®ÀÎ http://rth.dk/resources/risearch/ ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Â (2004³â 7¿ù 8ÀÏÀÚ È¤Àº ÀÌÈÄ¿¡ ¾÷µ¥ÀÌÆ®µÈ) RiSearch ÆÐŰÁöÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2004-2061 (CVE)
°ü·Ã URL 10812 (SecurityFocus)
°ü·Ã URL 16817 (ISS)