English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22183
À§Çèµµ 20
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Lotus Domino ¼­¹ö¿¡´Â ³»ºÎ IP ÁÖ¼Ò ³ëÃâ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
Lotus Domino ¼­¹ö´Â À¥ ±â¹ÝÀÇ °øµ¿Á¦ÀÛ ¼ÒÇÁÆ®¿þ¾î¸¦ À§ÇÑ ¾îÇø®ÄÉÀÌ¼Ç ÇÁ·¹ÀÓ¿öÅ©(framework)·Î Windows ¿Í Unix µîÀÇ ¿©·¯ Ç÷§Æû¿¡¼­ µ¿ÀÛÇÑ´Ù. ÀÌ Lotus Domino ¼­¹ö Áß 5.0.8 ¹öÀüÀÇ °æ¿ì, °ø°ÝÀڵ鿡°Ô À¥ ¼­¹öÀÇ ½ÇÁ¦ ³»ºÎ IP ÁÖ¼Ò¸¦ ³ëÃâÇÏ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ÀÌ Ãë¾àÁ¡Àº °ø°ÝÀÚµéÀÎ ´ÙÀ½°ú °°ÀÌ Àß Á¶ÀÛµÈ GET ¿äûÀ» ¼­¹ö¿¡ Àü´ÞÇÒ ¶§ ¹ß»ýÇÑ´Ù:

GET //////////// HTTP/1.0

ÀÌ·¯ÇÑ ¿äûÀ» ¹ÞÀº ¼­¹ö´Â ´ÙÀ½°ú °°ÀÌ ½ÇÁ¦ ³»ºÎ IP ÁÖ¼Ò¸¦ ´ã°í ÀÖ´Â ¿¡·¯ ¸Þ½ÃÁö¸¦ °ø°ÝÀڵ鿡°Ô ¹ÝȯÇÑ´Ù.

Error 404
Not found - file doesn't exist or is read protected [even tried multi
<A HREF="http://11.106.99.40/">
.....

ÀÌ Á¤º¸´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ º¸´Ù Áö´ÉÀûÀÎ °ø°ÝÀ» ¼öÇàÇÏ´Â µ¥ ÀÌ¿ëÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.kb.cert.org/vuls/id/133771
http://archives.neohapsis.com/archives/bugtraq/2001-09/0166.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Lotus Domino 5.0.8
ÇØ°áÃ¥ Lotus À¥ »çÀÌÆ® http://www.ibm.com/developerworks/lotus/downloads.html À» ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ Lotus·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2001-1018 (CVE)
°ü·Ã URL 3350 (SecurityFocus)
°ü·Ã URL (ISS)