English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21031
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í Count.cgi´Â ÀζóÀÎ À̹ÌÁö·Î½á À¥ÆäÀÌÁö»ó¿¡ ¹æ¹®È½¼ö¸¦ º¸¿©ÁÖ´Â CGI·Î ¸¹ÀÌ »ç¿ëµÇ°í ÀÖ´Ù. ±×·¯³ª »ç¿ëÀÚ¿¡ ÀÇÇØ °Ç³×Áö´Â Àμöµé¿¡ ´ëÇØ ºÒÃæºÐÇÑ bound üũ¶§¹®¿¡ Count.cgi ÇÁ·Î±×·¥ÀÌ ½ÇÇàµÉ ¶§ Buffer Overflow¸¦ ¹ß»ý½ÃŲ´Ù. À̸¦ ÀÌ¿ëÇϸé Attacker°¡ httpdÀÇ ±ÇÇÑÀ¸·Î ¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇà½Ãų ¼ö ÀÖ´Ù.

Count.cgi¸¦ ÀÌ¿ëÇÑ ÇØÅ·ÀÌ ½Ãµµ µÇ¾ú´ÂÁö¸¦ ¾Ë¾Æº¸±â À§Çؼ­´Â ¼­¹ö»óÀÇ access log ÆÄÀÏÀ» »ìÆìºÁ¾ß ÇÏ¸ç ´ÙÀ½°ú °°ÀÌ Count.cgi ÇÁ·Î±×·¥¿¡ ´ëÇÑ access ½Ãµµ¸¦ Ã¼Å©ÇØ º¼ ¼ö ÀÖ´Ù.

# grep -i 'Count.cgi' {WWW_HOME}/logs/access_log

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-1997-24.html
http://www.iss.net/security_center/static/586.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ Ãë¾àÁ¡ÀÌ ³²¾ÆÀÖ´Â 2.4 ¹Ì¸¸ÀÇ ¹öÀüÀÌ¸é ¹öÀü 2.4·Î ¾÷±×·¹À̵å Çϰųª ½ÇÇà ÆÛ¹Ì¼ÇÀ» Á¦°ÅÇØ¾ß ÇÑ´Ù.

1. ¹öÀü 2.4 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å
°¡´ÉÇÑÇÑ »¡¸® ÀÌ ¹®Á¦°¡ Á¦°ÅµÈ ¹öÀü 2.4 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÏ¸ç ´ÙÀ½ »çÀÌÆ®¿¡ °¡¸é ±× ¹öÀüÀ» ±¸ÇÒ ¼ö ÀÖ´Ù.
http://muquit.com/muquit/software/Count/Count.html

2. ½ÇÇà ÆÛ¹Ì¼Ç Á¦°Å ȤÀº ÆÄÀÏ »èÁ¦
»ç¿ëÇÏÁö ¾Ê´Â´Ù¸é Áï½Ã Count.cgi ÆÄÀÏÀ» »èÁ¦Çϰųª ½ÇÇà ÆÛ¹Ì¼ÇÀ» Á¦°ÅÇØ¾ß ÇÑ´Ù. Count.cgi´Â À¥ÆäÀÌÁö¿¡ ´ëÇÑ ¹æ¹®È½¼ö¸¦ Ä«¿îÆ®ÇÏ°í µð½ºÇ÷¹ÀÌÇØ ÁÖ´Â CGIÀÌ´Ù.
°ü·Ã URL CVE-1999-1590 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)