English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 27039
À§Çèµµ 40
Æ÷Æ® 135
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WMI
»ó¼¼¼³¸í ¿ø°Ý ½Ã½ºÅÛ¿¡´Â IIS°¡ °¡µ¿ÁßÀÌ´Ù. IIS´Â À¥ ¼­ºñ½º¸¦ Á¦°øÇØÁÖ´Â À¯¿ëÇÑ ¼­ºñ½ºÀ̳ª ÇÁ·ÎÆÄÀϸµ, ¼­ºñ½º °ÅºÎ, ºÒ¹ýÀûÀÎ Á¢±Ù, ÀÓÀÇÀÇ ÄÚµå½ÇÇà, Á¤º¸ °ø°³, ¹ÙÀÌ·¯½º, ¿ú, Æ®·ÎÀ̸ñ¸¶µîÀÇ À§Çù¿¡ ³ëÃâ µÉ ¼öÀÖ´Ù.

* º» Ãë¾àÁ¡Àº ¾ÈÇàºÎ °í½Ã»çÇ×(Á¦2012-54È£)ÀÇ ºÎ·Ï(Ãë¾àÁ¡ ºÐ¼®Æò°¡ ±â¼úÀû Á¡°ËÇ׸ñ ¼³¸í¼­)¿¡ ¸í½ÃµÈ ¼­ºñ½º¸í(IISADMIN)À» Á¡°ËÇÑ´Ù. ¼­ºñ½º¸íÀÌ ´Ù¸¦°æ¿ì °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows ¸ðµç ¹öÀü
ÇØ°áÃ¥ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é IIS À¥ ¼­ºñ½º¸¦ ÁßÁöÇÑ´Ù.

1. ½ÇÇàâ(Win Key + R)¿¡¼­ services.msc¸¦ ½ÇÇàÇÑ´Ù.
2. IIS Admin Service ¼±Åà ÈÄ ¼Ó¼º¿¡¼­ ½ÃÀÛÀ¯Çü->»ç¿ë¾ÈÇÔ, ½ÃÀÛ »óÅÂ->ÁßÁö ·Î ¼³Á¤ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)