Ãë¾àÁ¡ID |
22163 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
MacOS X Ŭ¶óÀÌ¾ðÆ®¸¦ °¡Áö°í ÀÖ´Â ÇØ´ç Apache À¥ ¼¹ö´Â ¼û°ÜÁø ÆÄÀϷκÎÅÍ Àε¦½Ì Á¤º¸¸¦ ³ëÃâÇÑ´Ù. ³»¿ë±â¹Ý °Ë»ö(Finder-By-Content) ±â´ÉÀ» °¡Áø MacOS X ´Â °¢ µð·ºÅ丮 ¾È¿¡ Á¸ÀçÇÏ´Â ÆÄÀϵéÀÇ ³»¿ëÀ» ±â¹ÝÀ¸·Î Àε¦½Ì µ¥ÀÌÅÍ(indexing data)¸¦ ÀÛ¼ºÇÑ´Ù. ÀÛ¼ºµÈ Àε¦½Ì µ¥ÀÌÅÍ´Â °¢ µð·ºÅ丮 ¾È¿¡ ¼û±è ÆÄÀÏ ".FBCIndex" À» »ý¼ºÇÏ¿© ÀúÀåÇϸç ÀÌ ÆÄÀÏÀº ´©±¸³ª ÀÐÀ» ¼ö ÀÖ´Â ±ÇÇÑ(world-readable)À» °®´Â´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº ÀÌ·¯ÇÑ °áÇÔÀ» ÀÌ¿ëÇÏ¿©, MacOS X Ŭ¶óÀÌ¾ðÆ®¸¦ °®´Â Apache ¼¹ö¿¡ ´ÙÀ½°ú °°Àº URL À» Àü´ÞÇÔÀ¸·Î½á ¼¹ö »óÀÇ À妽º µ¥ÀÌÅ͸¦ ȹµæÇÒ ¼ö ÀÖ´Ù.
http://apache_server/target_directory/.FBCIndex
¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ¿Í °°Àº ¹æ¹ýÀ¸·Î ÀáÁ¤ÀûÀÎ ÆÐ½º¿öµå, ½Ã½ºÅÛ ¼³Á¤, ¼³Ä¡µÈ ÀÀ¿ëÇÁ·Î±×·¥ µîµîÀÇ Áß¿äÇÑ Á¤º¸¸¦ ¾òÀ» ¼ö ÀÖÀ¸¸ç À̸¦ ±â¹ÝÀ¸·Î ´ë»ó ¼¹ö¿¡ º¸´Ù Áö´ÉÀûÀÎ °ø°ÝÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: ´ÙÀ½ MacOS X Ŭ¶óÀÌ¾ðÆ®¸¦ °®´Â Apache 1.3.14 À¥ ¼¹ö - Apple MacOS X 10.0 - Apple MacOS X 10.0.1 - Apple MacOS X 10.0.2 - Apple MacOS X 10.0.3 - Apple MacOS X 10.0.4 |
ÇØ°áÃ¥ |
ÃֽйöÀüÀÇ Apple MacOS X (10.1 ÀÌ»ó)·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù. http://support.apple.com/kb/HT1222?viewlocale=en_US
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ¸ðµç ¼û±ä ÆÄÀÏÀÇ ¾×¼¼½º(access)¸¦ ¹æÁöÇϱâ À§ÇØ ¼³Á¤ ÆÄÀÏ httpd.conf ¾È¿¡ ´ÙÀ½°ú °°ÀÌ <FilesMatch> Áö½ÃÀÚ¸¦ »ç¿ëÇÑ´Ù:
<FilesMatch "^\."> Order allow, deny Deny from all </FilesMatch> |
°ü·Ã URL |
CVE-2001-1446 (CVE) |
°ü·Ã URL |
3316,3324,3325 (SecurityFocus) |
°ü·Ã URL |
7103 (ISS) |
|