English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22153
À§Çèµµ 40
Æ÷Æ® 8080
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ÇØ´ç Apache Tomcat ¼­¹ö¿¡´Â µðÆúÆ® °èÁ¤(default account)ÀÌ Á¸ÀçÇÑ´Ù.
Jakarta Apache Tomcat ¼­¹ö´Â Java Servlet Pages(JSP) ¿Í Java servletsÀ» Áö¿øÇϱâ À§ÇØ Apache À¥ ¼­¹ö¿¡ »ç¿ëµÇ´Â ÀÚ¹Ù ¾îÇø®ÄÉÀÌ¼Ç ¼­¹öÀÌ´Ù. ÀÌ Apache Tomcat ¼­¹ö´Â Ãʱ⠼³Ä¡ ½Ã µðÆúÆ®·Î ¼³Á¤µÇ´Â ´ÙÀ½°ú °°Àº ´Ù¼öÀÇ µðÆúÆ® °èÁ¤(default account)µéÀÌ Á¸ÀçÇÑ´Ù.

"admin:tomcat"
"admin:admin"
"tomcat:tomcat"
"admin:tomcat"
"root:root"
"role1:role1"
"role:changethis"
"root:changethis"
"tomcat:changethis"

°èÁ¤¿¡ ´ëÇÑ °ü¸®´Â ¼­¹ö¿¡ ´ëÇÑ ºÒ¹ýÀûÀÎ Á¢±ÙÀ» ¹æÁöÇÏ´Â µ¥¿¡ ÀÖ¾î ¸Å¿ì Áß¿äÇÏ´Ù. ¸¸¾à, ÀÌ·¯ÇÑ µðÆúÆ® °èÁ¤µéÀÌ ¹æÄ¡µÉ °æ¿ì ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¼­¹ö¿¡ ½±°Ô ¾×¼¼½º ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖÀ¸¸ç ¼­ºñ½º¿¡ ´ëÇÑ ¼³Á¤À» º¯°æÇÏ´Â µîÀÇ ÀÓÀÇÀÇ ºÒ¹ýÀûÀÎ ÇàÀ§¸¦ ÇàÇÒ ¼ö ÀÖ´Ù.
ÇØ°áÃ¥ µðÆúÆ® °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå¸¦ º¯°æÇϰųª »èÁ¦ÇØ¾ß ÇÑ´Ù.

1. [Tomcat ¼³Ä¡ µð·ºÅ丮] ¡æ conf ¡æ users µð·ºÅ丮·Î À̵¿ÇÑ´Ù.
2. Çö µð·ºÅ丮¿¡¼­ admin-users.xml ÆÄÀÏÀ» ¿¬´Ù.
3. µðÆúÆ® °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå¸¦ º¯°æÇϰųª »èÁ¦ÇÑ´Ù.

º¸´Ù ÀÚ¼¼ÇÑ Á¤º¸´Â Apache Jakarta Project À¥ ÆäÀÌÁö¸¦ ÅëÇØ ¾òÀ» ¼ö ÀÖ´Ù. :
http://jakarta.apache.org/tomcat/
°ü·Ã URL CVE-1999-0508 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)