English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29084
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç HP Web JetAdmin ¼­¹ö´Â ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù.
HP JetAdmin ¼ÒÇÁÆ®¿þ¾î´Â À¥ ºê¶ó¿ìÀú¸¦ ÀÌ¿ëÇÏ¿© HP JetDirect¿¡ Á¢¼ÓµÈ ÇÁ¸°Å͵éÀ» °ü¸®ÇÑ´Ù. JetAdmin 7.x ¹öÀüµéÀº ¿ø°ÝÁöÀÇ ÀÎÁõµÈ °ø°ÝÀÚ°¡ ´ÙÀ½°ú °°Àº ´Ù¾çÇÑ ÇൿµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù:

1. '/plugins/hpjdwm/script/test/setinfo.hts' ½ºÅ©¸³Æ®´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ µð·ºÅ丮µéÀ» Ž»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
2. '/plugins/hpjwja/script/devices_update_printer_fw_upload.hts' ½ºÅ©¸³Æ®´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ /plugins/hpjwja/firmware/printer/ µð·ºÅ丮¿¡ ÀÓÀÇÀÇ ÆÄÀÏÀ» ¾÷·Îµå ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
3. '/plugins/framework/script/tree.xms' ½ºÅ©¸³Æ®´Â ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2004-03/0242.html
http://archives.neohapsis.com/archives/bugtraq/2004-03/0237.html


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Hewlett-Packard JetAdmin 7.x
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© HP Web Jetadmin 7.6 ÀÌ»ó ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
http://h20331.www2.hp.com/hpsub/cache/332262-0-0-225-121.html?jumpid=ex_r2845_go/webjetadmin/gc121306

Àӽà Á¶Ä¡¹æ¹ýµé:
HP Web Jet Admin ¼­ºñ½º¸¦ À§ÇÑ ÆÐ½º¿öµå¸¦ ¼³Á¤Çϱâ À§Çؼ­´Â ´ÙÀ½ ´Ü°èµéÀ» µû¶ó¾ß ÇÑ´Ù:
1. À¥ ºê¶ó¿ìÀú ¸Þ´º¿¡¼­ ÀÏ¹Ý ¼³Á¤(General Settings)À» ¼±ÅÃÇÏ°í Æ®¸®¸¦ È®ÀåÇÑ´Ù.
2. ÇÁ·ÎÆÄÀÏ °ü¸®(Profiles Administration)¸¦ È®ÀåÇÑ´Ù.
3. Ãß°¡/»èÁ¦ ÇÁ·ÎÆÄÀÏ(Add/Remove Profiles)À» ¼±ÅÃÇÑ´Ù.
4. »ç¿ëÀÚ ÇÁ·ÎÆÄÀÏ ÆäÀÌÁö¿¡¼­ ÆÐ½º¿öµå°¡ ¼³Á¤µÇ¾î ÀÖÁö ¾Ê´Ù¸é 'Note: To enable security features, an Admin password must be set.' ¸µÅ©¸¦ ¼±ÅÃÇÑ´Ù.
5. °ü¸®ÀÚ ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÑ´Ù.

IP Áּҵ鿡 ÀÇÇØ Á¦ÇÑÇÒ °ÍÀ¸·Î °­·ÂÈ÷ ±Ç°íÇÑ´Ù.
1. ÀÏ¹Ý ¼³Á¤(General Settings)ÀÇ Æ®¸®¸¦ È®ÀåÇÑ´Ù.
2. HTTP (À¥) ºÎºÐÀ» ¼±ÅÃÇÑ´Ù.
3. 'Allow HP Web Jetadmin Access' ¾Æ·¡¿¡¼­ °ü¸® IP È£½ºÆ®³ª ¹üÀ§¸¦ Ãß°¡ÇÑ´Ù. HP´Â ¶ÇÇÑ test µð·ºÅ丮¿¡ Æ÷ÇԵǾî ÀÖ´Â ¸ðµç ÆÄÀϵéÀ» Á¦°ÅÇÒ °ÍÀ¸·Î ±Ç°íÇϰí ÀÖ´Ù. µðÆúÆ® ¼³Ä¡ ½Ã ÀÌ µð·ºÅ丮´Â C:\Program Files\HP Web Jetadmin\doc\plugins\hpjdwm\script\ ¿¡ À§Ä¡ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 9973 (SecurityFocus)
°ü·Ã URL 15605,15606,15607 (ISS)