English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22163
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í MacOS X Ŭ¶óÀÌ¾ðÆ®¸¦ °¡Áö°í ÀÖ´Â ÇØ´ç Apache À¥ ¼­¹ö´Â ¼û°ÜÁø ÆÄÀϷκÎÅÍ Àε¦½Ì Á¤º¸¸¦ ³ëÃâÇÑ´Ù.
³»¿ë±â¹Ý °Ë»ö(Finder-By-Content) ±â´ÉÀ» °¡Áø MacOS X ´Â °¢ µð·ºÅ丮 ¾È¿¡ Á¸ÀçÇÏ´Â ÆÄÀϵéÀÇ ³»¿ëÀ» ±â¹ÝÀ¸·Î Àε¦½Ì µ¥ÀÌÅÍ(indexing data)¸¦ ÀÛ¼ºÇÑ´Ù. ÀÛ¼ºµÈ Àε¦½Ì µ¥ÀÌÅÍ´Â °¢ µð·ºÅ丮 ¾È¿¡ ¼û±è ÆÄÀÏ ".FBCIndex" À» »ý¼ºÇÏ¿© ÀúÀåÇϸç ÀÌ ÆÄÀÏÀº ´©±¸³ª ÀÐÀ» ¼ö ÀÖ´Â ±ÇÇÑ(world-readable)À» °®´Â´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº ÀÌ·¯ÇÑ °áÇÔÀ» ÀÌ¿ëÇÏ¿©, MacOS X Ŭ¶óÀÌ¾ðÆ®¸¦ °®´Â Apache ¼­¹ö¿¡ ´ÙÀ½°ú °°Àº URL À» Àü´ÞÇÔÀ¸·Î½á ¼­¹ö »óÀÇ À妽º µ¥ÀÌÅ͸¦ ȹµæÇÒ ¼ö ÀÖ´Ù.

http://apache_server/target_directory/.FBCIndex

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ¿Í °°Àº ¹æ¹ýÀ¸·Î ÀáÁ¤ÀûÀÎ ÆÐ½º¿öµå, ½Ã½ºÅÛ ¼³Á¤, ¼³Ä¡µÈ ÀÀ¿ëÇÁ·Î±×·¥ µîµîÀÇ Áß¿äÇÑ Á¤º¸¸¦ ¾òÀ» ¼ö ÀÖÀ¸¸ç À̸¦ ±â¹ÝÀ¸·Î ´ë»ó ¼­¹ö¿¡ º¸´Ù Áö´ÉÀûÀÎ °ø°ÝÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
´ÙÀ½ MacOS X Ŭ¶óÀÌ¾ðÆ®¸¦ °®´Â Apache 1.3.14 À¥ ¼­¹ö
- Apple MacOS X 10.0
- Apple MacOS X 10.0.1
- Apple MacOS X 10.0.2
- Apple MacOS X 10.0.3
- Apple MacOS X 10.0.4
ÇØ°áÃ¥ ÃֽйöÀüÀÇ Apple MacOS X (10.1 ÀÌ»ó)·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://support.apple.com/kb/HT1222?viewlocale=en_US

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, ¸ðµç ¼û±ä ÆÄÀÏÀÇ ¾×¼¼½º(access)¸¦ ¹æÁöÇϱâ À§ÇØ ¼³Á¤ ÆÄÀÏ httpd.conf ¾È¿¡ ´ÙÀ½°ú °°ÀÌ <FilesMatch> Áö½ÃÀÚ¸¦ »ç¿ëÇÑ´Ù:

<FilesMatch "^\.">
Order allow, deny
Deny from all
</FilesMatch>
°ü·Ã URL CVE-2001-1446 (CVE)
°ü·Ã URL 3316,3324,3325 (SecurityFocus)
°ü·Ã URL 7103 (ISS)