English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 210090
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö´Â ¾ÇÀÇÀûÀÎ JavaScript ÆÄÀϵé·ÎÀÇ ¸µÅ©µéÀ» Æ÷ÇÔÇÏ°í ÀÖ´Ù. ÀÌ´Â ´ë»ó À¥ »çÀÌÆ®°¡ ÀÎÅÍ³Ý ¿ú¿¡ °¨¿°µÇ¾úÀ½À» ÀǹÌÇÏ¸ç ¶ÇÇÑ À¥ »çÀÌÆ® ¹æ¹®°´µéµµ °¨¿°µÉ ¼ö ÀÖÀ½À» ÀǹÌÇÑ´Ù. ÀÌ´Â ¶ÇÇÑ °¨¿°µÈ À¥ »çÀÌÆ®°¡ SQL ÁÖÀÔ °ø°Ýµé¿¡ Ãë¾àÇÏ´Ù´Â °ÍÀ» ¸»ÇÑ´Ù. °ø°ÝÀÚµéÀº À¥ ¾îÇø®ÄÉÀÌ¼Ç °³¹ßÀ» À§ÇÑ º¸¾È¿¡ À־ÀÇ ¸ð¹ü»ç·Ê(best practices)¸¦ µû¸£Áö ¾Ê´Â À¥ ÆäÀÌÁöµé¿¡ SQL ÁÖÀÔ Ãë¾àÁ¡µéÀ» ÀÌ¿ëÇÒ ¼ö ÀÖ´Â ÀÚµ¿È­µÈ °ø°ÝÀ» °³¹ßÇØ ³õ¾Ò´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ´ë»ó À¥ »çÀÌÆ®¿¡ ¼öÁýµÈ À¥ ÆäÀÌÁöµé ³»¿¡¼­ uc8010-dot-com ±×¸®°í ucmal-dot-com·ÎÀÇ ¸µÅ©µéÀÌ ¹ß°ßµÇ´ÂÁö¸¦ Á¡°ËÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://isc.sans.org/diary.html?storyid=3810
http://secunia.com/advisories/28276/
http://www.kb.cert.org/vuls/id/871673
http://explabs.blogspot.com/2008/01/so-this-is-kind-of-interesting.html
http://blogs.iis.net/bills/archive/2008/04/25/sql-injection-attacks-on-iis-web-servers.aspx

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
¸ðµç HTTP ¼­¹ö ¸ðµç ¹öÀü
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ °¨¿°µÈ À¥ »çÀÌÆ®¸¦ ¿ø »óÅ·Πº¹¿øÇÏ°í ¸ðµç µ¿Àû ÆäÀÌÁöµéÀ» SQL ÁÖÀÔ Ãë¾àÁ¡µé¿¡ ´ëÇØ °ËÁõÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2008-0098 (CVE)
°ü·Ã URL 27091 (SecurityFocus)
°ü·Ã URL (ISS)