Ãë¾àÁ¡ID |
22154 |
À§Çèµµ |
40 |
Æ÷Æ® |
8888 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Netscape Enterprise ¼¹ö´Â µðÆúÆ® °ü¸®ÀÚ °èÁ¤ "admin/admin" ÀÌ Á¸ÀçÇÑ´Ù. Netscape(ÇöÀç : iPlanet) Enterprise ¼¹ö´Â Sun-Netscape Alliance ¿¡ ÀÇÇØ Á¦°øµÇ´Â À¥(HTTP) ¼¹ö Á¦Ç°ÀÌ´Ù. ÀÌ ¼¹ö´Â Ãʱ⠼³Ä¡ ½Ã ¼³Á¤µÈ ƯÁ¤ Æ÷Æ®(8888/TCP ) »ó¿¡¼ µ¿ÀÛÇÏ´Â °ü¸®ÀÚ À¥ ÀÎÅÍÆäÀ̽º°¡ Áö¿øµÈ´Ù. ÇØ´ç ¼¹ö¿¡´Â °èÁ¤¸í°ú ÆÐ½º¿öµå°¡ "admin"À¸·Î µ¿ÀÏÇÑ µðÆúÆ® °ü¸®ÀÚ °èÁ¤ÀÌ Á¸ÀçÇÏ¿© À̸¦ ÅëÇØ °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¿¡ Á¢±ÙÇÒ ¼ö ÀÖ´Ù. °èÁ¤ °ü¸®´Â ¼¹ö »ó¿¡ ºÒ¹ýÀûÀÎ Á¢±ÙÀ» ¹æÁöÇϱâ À§ÇØ °í·ÁÇØ¾ßÇÒ Áß¿äÇÑ ¿ä¼ÒÀÌ´Ù. ¸¸¾à, ÀÌ µðÆúÆ® °ü¸®ÀÚ °èÁ¤ÀÌ ±×´ë·Î ¹æÄ¡µÇ´Â °æ¿ì, ¿ø°ÝÁö °ø°ÝÀÚµéÀº À¥ °ü¸®ÀÚ ÆäÀÌÁö Á¢¼ÓÇÏ¿© ȯ°æ ¼³Á¤À» ÀÓÀÇ·Î º¯°æÇÏ¿© ¼ºñ½º °ÅºÎ(Denial of Service) »óÅ¿¡ À̸£°Ô Çϰųª ¼¹ö¿¡ ´ëÇÑ ¾×¼¼½º(access) ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ´Ù. |
ÇØ°áÃ¥ |
°èÁ¤¿¡ ´ëÇÑ µðÆúÆ® ÆÐ½º¿öµå¸¦ ÃßÃøÀÌ ¾î·Á¿î °ÍÀ¸·Î º¯°æÇÏ¿©¾ß ÇÑ´Ù.
1. À¥ ºê¶ó¿ìÀú¸¦ ÅëÇØ Enterprise Administration Server : http://hostname.domain_name:administration_port ¿¡ Á¢¼ÓÇÑ´Ù. 2. "Preference" ÅÇÀ» Ŭ¸¯ÇÑ ÈÄ Superuser Access Control ¸µÅ©¸¦ Ŭ¸¯ÇÑ´Ù. 3. Authentication User Name Çʵ忡 "admin" °ü¸®ÀÚ °èÁ¤À» ÀÔ·ÂÇÑ´Ù. 4. Authentication Password Çʵ忡 »õ·Î¿î ÆÐ½º¿öµå¸¦ ÀÔ·ÂÇÑ ÈÄ ÀçÈ®ÀÎÇÑ´Ù. 5. ¸ðµç ÀÔ·ÂÀÌ ³¡³ª¸é [OK] ¹öưÀ» Ŭ¸¯ÇÏ¿© Àû¿ëÇÑ´Ù. |
°ü·Ã URL |
CVE-1999-0508 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|