| Ãë¾àÁ¡ID |
21006 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ Frontpage extensions°¡ ÀÛµ¿ÁßÀÎ °ÍÀ¸·Î ³ªÅ¸³ª¸ç 'service.pwd' ÆÄÀÏÀÌ ´Ù¿î·ÎµåµÈ´Ù. 'service.pwd' ÆÄÀÏÀº FrontPage À¥¿¡ ´ëÇÑ »ç¿ëÀÚ ¹× ÆÐ½º¿öµå ¸®½ºÆ®¸¦ Æ÷ÇÔÇϰí ÀÖÀ¸¸ç, IIS¿Í WebSite ¼¹ö¿¡¼´Â »ç¿ëµÇÁö ¾Ê´Â´Ù. ÀÌ ÆÄÀϵéÀº ¿ÜºÎ·Î ºÎÅÍ attacker¿¡ ÀÇÇØ °Ë»öµÇ¾î offlineÀ¸·Î crackµÉ ¼ö ÀÖ´Â ¾ÏÈ£ÈµÈ ÆÐ½º¿öµåµéÀ» Æ÷ÇÔÇϰí ÀÖ´Ù. ¸¸¾à ÆÐ½º¿öµåµéÀÌ ½±°Ô crack µÈ´Ù¸é attacker´Â ã¾ÆÁø ÆÐ½º¿öµå¸¦ ÀÌ¿ëÇÏ¿© ¼¹ö resource¸¦ access ÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/1205 http://xforce.iss.net/xforce/xfdb/3391
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Netscape ¼¹ö |
| ÇØ°áÃ¥ |
1. ÇÊ¿äÇÏÁö ¾Ê´Ù¸é Frontpage extentions¸¦ Áï½Ã Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.
2. FrontPage °èÁ¤µé¿¡ ´ëÇÑ ÆÐ½º¿öµå¸¦ attacker°¡ °¡Á®°¡´õ¶óµµ crackÇÏ±â ¾î·Æ°Ô ¼³Á¤ÇÑ´Ù. ¶ÇÇÑ _vti_pvt µð·ºÅ丮¿Í *.pwd ÆÄÀϵ鿡 ´ëÇÑ Á¢±Ù±ÇÇÑÀ» Remote Attacker°¡ ¾×¼¼½ºÇÒ ¼ö ¾øµµ·Ï ¼öÁ¤ÇÏ¿©¾ß ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶Ä¡¹æ¹ýÀº FrontPage ¼¹öÀÇ Á¤»óÀûÀÎ ÀÛµ¿¿¡´Â ¾Æ¹«·± ¿µÇâÀ» ¹ÌÄ¡Áö ¾Ê´Â´Ù.
3. FrontPage Server ententionsÀÇ °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|