English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22221
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç MyServer À¥ ¼­¹ö´Â dot dot ½ÃÄö½º¸¦ ÅëÇÑ µð·ºÅ丮 Ž»ö Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
MyServer´Â MS Windows ¿Í Linux ±â¹ÝÀÇ Ç÷§ÆûµéÀ» À§ÇÑ ¹«·á·Î »ç¿ë °¡´ÉÇÑ À¥ ¼­¹öÀÌ´Ù. MyServer ¹öÀü 0.4.2¿Í 0.4.1¿¡´Â À¥ ¼­¹ö »óÀÇ À¥ ·çÆ® µð·ºÅ丮 ¿ÜºÎ¿¡ Á¸ÀçÇÏ´Â ÀÓÀÇÀÇ µð·ºÅ丮¸¦ Ž»öÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. ¿ø°ÝÁö °ø°ÝÀÚµéÀº ´ÙÀ½°ú °°ÀÌ À¥ ¼­¹ö¿¡ ÀÎÄÚµùµÈ "dot dot" ½ÃÄö½º¸¦ »ç¿ëÇØ Àß Á¶ÀÛµÈ URL ¿äûÀ» ¼­¹ö¿¡ Àü´ÞÇÔÀ¸·Î½á, À¥ ¼­¹ö »óÀÇ ÀÓÀÇÀÇ µð·ºÅ丮 Ž»ö ¹× µð·ºÅ丮¿Í ÆÄÀÏ ³»¿ëÀ» º¼ ¼ö ÀÖ´Ù.

http://[target_server]/%2e%2e/%2e%2e/%2e%2e
http://[target_server]/%2e%2e/%2e%2e/%2e%2e/boot.ini

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/securitynews/5EP0D1FAAA.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
MyServer myServer 0.4.1
MyServer myServer 0.4.2
ÇØ°áÃ¥ ´ÙÀ½ MyServer À¥ »çÀÌÆ®¸¦ Âü°íÇÏ¿© MyServerÀÇ °¡Àå ÃֽйöÀü(0.5 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://sourceforge.net/project/showfiles.php?group_id=63119
°ü·Ã URL (CVE)
°ü·Ã URL 7944 (SecurityFocus)
°ü·Ã URL 12272 (ISS)