Ãë¾àÁ¡ID |
22186 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç Apache Tomcat mod_jk moduleÀÇ ¹è³ÊÁ¤º¸¿¡ ÀÇÇÏ¸é ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. Ãë¾àÇÑ mod_jk ¸ðµâÀ» »ç¿ëÇÏ´Â ÇØ´ç Apache À¥¼¹ö¿Í Tomcat ¼¹ö´Â ¼ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù. Apache À¥ ¼¹ö¿Í Tomcat ¼¹ö´Â Apache ÇÁ·ÎÁ§Æ®¿¡ ÀÇÇØ¼ À¯ÁöµÇ°í ¹èÆ÷µÇ´Â ¼¹öµé·Î Unix, Linux, MS Windows Ç÷§Æû ¸ðµÎ¿¡¼ µ¿ÀÛÇϵµ·Ï Á¦À۵Ǿú´Ù. ÀÌ Áß mod_jk 1.2 ¸¦ »ç¿ëÇÏ´Â ÀϺΠ¼¹ö´Â ¼ºñ½º °ÅºÎ(Denial of Service) °ø°Ý¿¡ Ãë¾àÇÏ´Ù. mod_jk ´Â Apache À¥ ¼¹ö¿Í Tomcat ¼¹ö »çÀÌÀÇ ºê¸´Áö(bridge) ¿ªÇÒÀ» ´ã´çÇÏ´Â Apache ¸ðµâ·Î¼ 80¹ø Æ÷Æ®¸¦ ÅëÇÑ ÀϹÝÀûÀÎ À¥ ¿äû(request) µéÀº Apache ¼¹ö¿¡ ÀÇÇØ¼ ó¸®µÇ°í ´ÙÀ½À¸·Î ÀÚ¹Ù ¼ºí¸´(Java Servlet)°ú JSP ¿äû(request)Àº Tomcat ¼¹ö¿¡°Ô Àü´ÞµÈ´Ù. ÀÌ ¸ðµâÀº Apache Jserv Protocol 1.3(AJP 1.3) ¸¦ ºñ·ÔÇÑ ´Ù¼öÀÇ ÇÁ·ÎÅäÄÝÀ» Áö¿øÇÑ´Ù. ÀÌ ¼ºñ½º °ÅºÎ Ãë¾àÁ¡Àº ¸ðµâÀÇ À߸øµÈ ¼³°è·Î ÀÎÇÏ¿© ¹ß»ýÇϴµ¥ ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ´ÙÀ½°ú °°Àº Á¶ÀÛµÈ chunked encoding ¿äûÀ» Apache À¥ ¼¹ö¿¡ Àü´ÞÇÔÀ¸·Î½á, Apache ¿Í Tomcat °£ Åë½ÅÀÇ µ¿±â(synchronize)ȸ¦ È寮·¯¶ß¸± ¼ö ÀÖ´Ù:
GET /index.jsp HTTP/1.1 Host: X.X.X.X Transfer-Encoding: Chunked
53636f7474 ºñÁ¤»óÀûÀÎ chunked Àü¼Û encodingÀ» »ç¿ëÇÏ´Â index.jsp ÆÄÀÏ¿¡ ´ëÇÑ ´Ù·®ÀÇ HTTP GET ¿äûµéÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ³×Æ®¿öÅ© ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖ´Ù. ÀÌ´Â Apache ¶Ç´Â Tomcat ¼¹ö°¡ Àç½ÃÀÛµÉ ¶§±îÁö ¼¹ö¸¦ »ç¿ëÇÏÁö ¸øÇÏ°Ô ¸¸µé ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇÏ¿© Apache mod_jk ¸ðµâÀÇ ¹è³ÊÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ (False Positive)¸¦ º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securiteam.com/unixfocus/6A0061F6AQ.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Apache Software Foundation Apache 1.3 Apache Software Foundation Apache 1.3.11/12/14 Apache Software Foundation Apache 1.3.17 - 1.3.20 Apache Software Foundation Apache 1.3.22 - 1.3.27 Apache Software Foundation mod_jk 1.2 Apache Software Foundation Tomcat 4.0 Apache Software Foundation Tomcat 4.0.1 - 4.0.5 Apache Software Foundation Tomcat 4.1 Apache Software Foundation Tomcat 4.1.10/12 Linux Any version Unix Any version Windows Any version |
ÇØ°áÃ¥ |
Jakarta À¥ »çÀÌÆ® http://archive.apache.org/dist/tomcat/tomcat-connectors/jk/ ¸¦ ÂüÁ¶ÇÏ¿© ¹®Á¦°¡ ÇØ°áµÈ mod_jk 1.2.1 ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
6320 (SecurityFocus) |
°ü·Ã URL |
10771 (ISS) |
|