English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21022
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ '/cgi-bin/bb-hist.sh' CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÀÌ ÆÄÀÏÀº ³×Æ®¿öÅ© °ü¸®ÀÚ°¡ À¥ ºê¶ó¿ìÁ ÅëÇØ¼­ ³×Æ®¿öÅ©¿Í ½Ã½ºÅÛµéÀÇ »óŸ¦ º¼ ¼ö ÀÖ°Ô ÇØ ÁÖ´Â À¯´Ð½º ±â¹ÝÀÇ Big Brother ³×Æ®¿öÅ© ¸ð´ÏÅ͸µ ÆÐŰÁöÀÇ history viewer ÇÁ·Î±×·¥ÀÌ´Ù. Áö±Ý±îÁö ÀÌ ÆÄÀÏ¿¡´Â µÎ°¡Áö Á¾·ùÀÇ Ãë¾àÁ¡µéÀÌ º¸°íµÇ¾ú´Ù.

1. Big BrotherÀÇ ¹öÀü 1.09b³ª ȤÀº 1.09cÀÌ ¼³Ä¡µÇ¾î ÀÖ´Â ½Ã½ºÅÛ »ó¿¡¼­ bb-hist.sh CGI ÇÁ·Î±×·¥¿¡ ÀÖ´Â °áÁ¡À» ÀÌ¿ëÇÏ¸é ½Ã½ºÅÛ»óÀÇ ÀÓÀÇÀÇ ÆÄÀÏµé º¼ ¼ö ÀÖ´Ù.

2. Big BrotherÀÇ ¹öÀü 1.5d2 ÀÌÇÏÀÇ ¹öÀü¿¡¼­´Â ÀÌ ÆÄÀÏÀ» ÀÌ¿ëÇØ¼­ »ç¿ëÀÚ¸íÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù. Big Brother°¡ ¿¡·¯ ¸Þ½ÃÁö¸¦ º¸¿©ÁÙ ¶§ Áß¿äÆÄÀÏ ¹× »ç¿ëÀÚ¸íÀÇ Á¸Àç¿©ºÎ¸¦ ¾Ë ¼ö ÀÖ´Ù. »ç¿ëÀÚ¸í Á¤º¸´Â Brute force °ø°Ý¿¡ »ç¿ëµÉ ¼ö ÀÖ´Ù.

Ÿ´çÇÏÁö ¾ÊÀº ¿äû¿¡ ´ëÇØ ¿¡·¯ ¸Þ¼¼Áö·Î Áß¿äÇÑ Á¤º¸¸¦ º¸¿©ÁÖ´Â ÆÄÀϵéÀº ´ÙÀ½°ú °°Àº °ÍµéÀÌ ÀÖ´Ù.
- bb-hist.sh
- bb-histlog.sh
- bb-hostsvc.sh
- bb-rep.sh
- bb-replog.sh
- bb-ack.sh

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
'/cgi-bin/bb-hist.sh' CGI
ÇØ°áÃ¥ Big BrotherÀÇ ÃֽйöÀü (1.5d3 ÀÌ»ó) À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÃֽйöÀüÀº Big BrotherÀÇ À¥»çÀÌÆ®¿¡¼­ (http://www.bb4.com/download.html) ±¸ÇÒ ¼ö ÀÖ´Ù.
°ü·Ã URL CVE-2000-1177 (CVE)
°ü·Ã URL 2869 (SecurityFocus)
°ü·Ã URL 3755 (ISS)