English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22250
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í ÇØ´ç Novell Groupwise servlet ¼­¹ö´Â µðÆúÆ® ÆÐ½º¿öµå¸¦ »ç¿ëÇϰí ÀÖ´Ù.
Novell Groupwise Servlet Gateway´Â NetWare v1.1.7b ±×¸®°í NetWare Enterprise À¥ ¼­¹ö¸¦ À§ÇÑ Novell JVM (Java Virtual Machine)ÀÌ´Ù. Novell GroupWise ¹öÀü 5.5 Enhancement Pack ±×¸®°í 6.0¿¡ ÀÖ´Â ¼­ºí¸´(Servlet) °ü¸®ÀÚ´Â ¼­ºí¸´ °ü¸®ÀÚ¸¦ À§ÇÑ µðÆúÆ® »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµå·Î ¼³Ä¡µÇ¾î ÀÖ´Ù. ¼­ºí¸´ °ü¸®ÀÚ´Â ¼­ºí¸´µéÀÇ È¯°æ±¸¼ºÀ» žÀç(load), žÀç ÇØÁö, ÀçžÀç ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¼­ºí¸´µéÀ» Á¦¾îÇϰí žÀç ÇØÁöÇÒ ¼ö ÀÖ´Â ´É·ÂÀº °ø°ÝÀÚ°¡ »ç¿ëÀڵ鿡 ´ëÇÑ À¥ ±â¹ÝÀÇ ¼­ºñ½ºµéÀ» °ÅºÎÇÏ°Ô ÇÒ ¼ö ÀÖ´Ù. ÀÌ´Â »ç¿ëÀÚµéÀÌ ¸ÞÀÏÀ̳ª ´Ù¸¥ ¼­ºí¸´ ±â¹ÝÀÇ ÀÚ¿øµéÀ» ¾×¼¼½ºÇÒ ¼ö ¾ø°Ô ÇÑ´Ù.

µðÆúÆ® ÆÐ½º¿öµå°¡ ¼³Á¤µÇ¾î ÀÖ´ÂÁö¸¦ Å×½ºÆ®Çϱâ À§Çؼ­´Â:
https://[targethost]/servlet/ServletManager/

»ç¿ëÀÚ¿¡ 'servlet' ±×¸®°í ÆÐ½º¿öµå·Î´Â 'manager'¸¦ ÀÔ·ÂÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/securitynews/6G00Q003FE.html


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Novell GroupWise 6.0
Novell GroupWise 5.5 Enhancement Pack
Netware 5
Microsoft Windows Any version
ÇØ°áÃ¥ µðÆúÆ® ÆÐ½º¿öµå¸¦ º¯°æÇÏ¿©¾ß ÇÑ´Ù.

1. SYS:\JAVA\SERVLETS\SERVLET.PROPERTIES ÆÄÀÏÀ» ¿ÀÇÂÇÑ´Ù.
2. ServletManager¸¦ À§ÇÑ ¼½¼Ç¿¡ ÀÖ´Â ´ÙÀ½ ¶óÀο¡ À§Ä¡ÇÑ »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµå¸¦ º¯°æÇÑ´Ù:
servlet.ServletManager.initArgs=datamethod=POST,user=servlet,password=manager,bgcolor

ÀÚ¼¼ÇÑ Á¤º¸¸¦ ¿øÇÑ´Ù¸é Novell ±â¼ú Á¤º¸ ¹®¼­ 10067329¸¦ Âü°íÇÑ´Ù:
http://support.novell.com/cgi-bin/search/searchtid.cgi?/10067329.htm
°ü·Ã URL CVE-2001-1195 (CVE)
°ü·Ã URL 3697 (SecurityFocus)
°ü·Ã URL 7701 (ISS)