Ãë¾àÁ¡ID |
22153 |
À§Çèµµ |
40 |
Æ÷Æ® |
8080 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
Servlet |
»ó¼¼¼³¸í |
ÇØ´ç Apache Tomcat ¼¹ö¿¡´Â µðÆúÆ® °èÁ¤(default account)ÀÌ Á¸ÀçÇÑ´Ù. Jakarta Apache Tomcat ¼¹ö´Â Java Servlet Pages(JSP) ¿Í Java servletsÀ» Áö¿øÇϱâ À§ÇØ Apache À¥ ¼¹ö¿¡ »ç¿ëµÇ´Â ÀÚ¹Ù ¾îÇø®ÄÉÀÌ¼Ç ¼¹öÀÌ´Ù. ÀÌ Apache Tomcat ¼¹ö´Â Ãʱ⠼³Ä¡ ½Ã µðÆúÆ®·Î ¼³Á¤µÇ´Â ´ÙÀ½°ú °°Àº ´Ù¼öÀÇ µðÆúÆ® °èÁ¤(default account)µéÀÌ Á¸ÀçÇÑ´Ù.
"admin:tomcat" "admin:admin" "tomcat:tomcat" "admin:tomcat" "root:root" "role1:role1" "role:changethis" "root:changethis" "tomcat:changethis"
°èÁ¤¿¡ ´ëÇÑ °ü¸®´Â ¼¹ö¿¡ ´ëÇÑ ºÒ¹ýÀûÀÎ Á¢±ÙÀ» ¹æÁöÇÏ´Â µ¥¿¡ ÀÖ¾î ¸Å¿ì Áß¿äÇÏ´Ù. ¸¸¾à, ÀÌ·¯ÇÑ µðÆúÆ® °èÁ¤µéÀÌ ¹æÄ¡µÉ °æ¿ì ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¼¹ö¿¡ ½±°Ô ¾×¼¼½º ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖÀ¸¸ç ¼ºñ½º¿¡ ´ëÇÑ ¼³Á¤À» º¯°æÇÏ´Â µîÀÇ ÀÓÀÇÀÇ ºÒ¹ýÀûÀÎ ÇàÀ§¸¦ ÇàÇÒ ¼ö ÀÖ´Ù. |
ÇØ°áÃ¥ |
µðÆúÆ® °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå¸¦ º¯°æÇϰųª »èÁ¦ÇØ¾ß ÇÑ´Ù.
1. [Tomcat ¼³Ä¡ µð·ºÅ丮] ¡æ conf ¡æ users µð·ºÅ丮·Î À̵¿ÇÑ´Ù. 2. Çö µð·ºÅ丮¿¡¼ admin-users.xml ÆÄÀÏÀ» ¿¬´Ù. 3. µðÆúÆ® °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå¸¦ º¯°æÇϰųª »èÁ¦ÇÑ´Ù.
º¸´Ù ÀÚ¼¼ÇÑ Á¤º¸´Â Apache Jakarta Project À¥ ÆäÀÌÁö¸¦ ÅëÇØ ¾òÀ» ¼ö ÀÖ´Ù. : http://jakarta.apache.org/tomcat/ |
°ü·Ã URL |
CVE-1999-0508 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|