English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22179
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â Microsoft IIS WebDAV ¼­ºñ½º°¡ °¡µ¿ ÁßÀÌ´Ù.
WebDAV (Web Distributed Authoring and Versioning)´Â À¥ ÄÁÅÙÆ® (RFC2518)¿¡ ´ëÇÑ ºÐ»ê Á¦ÀÛ ¹× ¹öÀü °ü¸®¸¦ Ãß°¡Çϱâ À§ÇØ °í¾ÈµÈ HTTP 1.1 ÇÁ·ÎÅäÄÝÀÇ È®ÀåÀÌ´Ù. WebDAVÀÇ ¸î¸î ¹öÀüµéÀº ½É°¢ÇÑ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ¾î ÀÌ ¼­ºñ½º´Â ÁÖÀÇ ±í°Ô »ç¿ëµÇ¾îÁ®¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2003-09.html
http://www.microsoft.com/technet/security/bulletin/ms03-007.asp
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2003-0109
http://www.iss.net/security_center/static/11533.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft IIS 4.0
Microsoft IIS 5.0
Microsoft IIS 6.0
Microsoft IIS 7.0
Microsoft IIS 8.0
Microsoft IIS 10.0
ÇØ°áÃ¥ ¸¸¾à IIS WebDAVÀÇ »ç¿ëÀÌ ÇÊ¿äÇÏ´Ù¸é, ÃÖ»óÀÇ º¸¾È»óŸ¦ À¯ÁöÇϱâ À§ÇÑ ÆÐÄ¡µéÀÌ Àû¿ëµÇ°Ô ÇÏ¿©¾ß ÇÑ´Ù.

-- ȤÀº --

¸¸¾à WebDAVÀÇ »ç¿ëÀÌ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ½Ã½ºÅÛÀ¸·ÎºÎÅÍ ÀÛµ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù. WebDAV¸¦ ÀÛµ¿ÁßÁö ½Ã۱â À§Çؼ­´Â:

1. IIS lockdown ÅøÀ» ÀÌ¿ëÇ϶ó. ÀÌ ÅøÀ» ´ÙÀ½ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù:
http://www.microsoft.com/download/en/details.aspx?id=25064

2. ¶Ç ´Ù¸¥ ¹æ¹ýÀ¸·Î, MicrosoftÀÇ Knowledgebase Article 241520, "How to Disable WebDAV for IIS 5.0"¿¡ ÀÖ´Â ¸í·ÉµéÀ» µû¸§À¸·Î½á ÀÛµ¿ÁßÁö ½Ãų ¼ö ÀÖ´Ù:
http://support.microsoft.com/default.aspx?scid=kb;en-us;241520

PUT°ú DELETE ¿äûÀ» Æ÷ÇÔÇÏ¿© WebDAV¸¦ ¿ÏÀüÈ÷ Disable ½Ã۱â À§Çؼ­ ·¹Áö½ºÆ®¸®¿¡¼­ ´ÙÀ½°ú °°Àº ¼öÁ¤À» °¡ÇÏ¿©¾ß ÇÑ´Ù.

1) ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ½ÃÀÛÇÑ´Ù. (Regedt32.exe).
2) ·¹Áö½ºÆ®¸®¿¡¼­ ´ÙÀ½ ۸¦ ã¾Æ Ŭ¸¯ÇÑ´Ù:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters

3) ÆíÁý ¸Þ´º¿¡¼­ °ª Ãß°¡¸¦ Ŭ¸¯ÇÏ°í ´ÙÀ½ ·¹Áö½ºÆ®¸® °ªÀ» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù:
°ª À̸§: DisableWebDAV
µ¥ÀÌÅÍ À¯Çü: DWORD
°ª µ¥ÀÌÅÍ: 1

3. ¶ÇÇÑ URLScanÀ» »ç¿ëÇÒ ¼ö Àִµ¥ ÀÌ´Â 'PROPFIND' ¸Þ½îµå¿¡ ´ëÇÑ À¥ ¿äûµéÀ» Â÷´ÜÇÒ ¼ö ÀÖ´Ù. URLScan¿¡ ´ëÇÑ Á¤º¸´Â ´ÙÀ½ »çÀÌÆ®¿¡¼­ ÀÌ¿ë °¡´ÉÇÏ´Ù:
http://support.microsoft.com/default.aspx?scid=kb;[LN];326444
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 11537 (ISS)