English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22158
À§Çèµµ 40
Æ÷Æ® 8080
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ÇØ´ç Apache Tomcat ¼­¹ö´Â Unicode ¹®ÀÚµéÀ» ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Jakarta TomcatÀº JavaServer Pages (JSP) ¿Í Java servlet µéÀ» Áö¿øÇÏ´Â Apache HTTP ¼­¹öµé°ú ÇÔ²² »ç¿ëµÇ´Â Java ¾îÇø®ÄÉÀÌ¼Ç ¼­¹öÀÌ´Ù. Tomcat 3.2.1 ÀÌÇÏ ¹öÀüµéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ À¥¼­¹ö»ó¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ »ç¿ëÀÚ´Â Unicode ¹®ÀÚµé·Î µÈ "dot dot" ½ÃÄö½ºµé (/%2e%2e/)À» Æ÷ÇÔÇÏ´Â URL ¿äûÀ» º¸³» À¥ RootÀÇ ¿ÜºÎ¿¡ ÀÖ´Â µð·ºÅ丮¿Í ÆÄÀϵéÀ» º¼ ¼ö ÀÖ´Ù.
À¥ ºê¶ó¿ìÁ ÀÌ¿ëÇÏ¿© ´ÙÀ½ URLÀ» º¸³¿À¸·Î½á Tomcat ¼­¹ö´Â Root ¹®¼­ µð·ºÅ丮 ¿ÜºÎ¿¡ ÀÖ´Â µð·ºÅ丮ÀÇ ³»¿ëÀ» ¸®½ºÆ®ÇØ ÁÙ °ÍÀÌ´Ù:

http://www.target.com:8080/%2e%2e/%2e%2e/%2e%2e/%00.jsp

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/2518
http://www.iss.net/security_center/static/6305.php
http://www.securiteam.com/windowsntfocus/5YP040U40M.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apache Tomcat ¸ðµç ¹öÀü
Windows Ç÷§Æû
UNIX/Linux Ç÷§Æû
ÇØ°áÃ¥ ´ÙÀ½ Jakarta À¥ »çÀÌÆ®·ÎºÎÅÍ Jakarta TomcatÀÇ °¡Àå ÃֽйöÀü (3.2.2b2 ÀÌ»ó)À» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://jakarta.apache.org/

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î server.xml¿¡ ÀÖ´Â connector Á¤ÀǺο¡ "inet" Àμö¸¦ Ãß°¡ÇÑ´Ù:
<Connector className="¡¦">
<Parameter name="handler" value="...">
<Parameter name="inet" value="localhost">
<Parameter name="port" value="8007">
</Connector>
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)