English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21038
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ "dumpenv.pl" CGI°¡ ¼³Ä¡µÇ¾î ÀÖÀ¸¸ç Sambar Web Server°¡ ÀÛµ¿ÁßÀÎ °ÍÀ¸·Î º¸ÀδÙ.
¸¹Àº Sambar Server 4.1 beta releaseµé¿¡´Â Ãë¾àÇÑ CGI¸¦ ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ³»ÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» ÀÐÀ» ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.

ÀÌ ¹ö±×¸¦ Å×½ºÆ® ÇØ º¸±â À§Çؼ­´Â perl script¸¦ ½ÇÇà½ÃÄÑ º¼ ¼ö ÀÖ´Ù.

http://www.victim.com/cgi-bin/dumpenv.pl

±×·¯¸é victim ÄÄÇ»ÅÍÀÇ À¥¼­¹ö path¸¦ Æ÷ÇÔÇÏ¿© ¿ÏÀüÇÑ È¯°æ¼³Á¤À» º¼ ¼ö ÀÖ´Ù. ¶ÇÇÑ ´ÙÀ½°ú °°ÀÌ urlÀ» ÁÖ°Ô µÇ¸é administrator·Î ·Î±×ÀÎÀ» ½ÃµµÇÒ ¼ö ÀÖ´Ù.

µðÆúÆ® ·Î±×ÀÎ ID : admin (µðÆúÆ® ÆÐ½º¿öµå´Â blank)

¸¸¾à victim ¼ÂÆÃÀ» ¹Ù²ÙÁö ¾Ê¾Ò´Ù¸é ±× ¼­¹ö¸¦ control ÇÒ ¼ö ÀÖ´Ù.

ÀÌ Ãë¾àÁ¡¿¡ ´õÇÏ¿© Sambar¼­¹ö¿¡´Â victimÀÇ HDD¸¦ º¼ ¼ö ÀÖ´Â ¶Ç´Ù¸¥ Ãë¾àÁ¡ÀÌ ÀÖ´Ù. perl ½ºÅ©¸³Æ®°¡ ÀÛµ¿Çϰí ÀÖ´Ù¸é ´ëºÎºÐÀÇ °æ¿ì ´ÙÀ½°ú °°ÀÌ path¸¦ Á༭ µð·ºÅ丮ÀÇ ³»¿ëÀ» º¼ ¼öµµ ÀÖ´Ù.

http://www.victim.com/c:/program files/sambar41

* Âü°í »çÀÌÆ®:
http://www.dataguard.no/bugtraq/1998_2/0511.html
http://www.uia.ac.be/u/peper/sambar/v41/security.htm
http://www.sambar.com/syshelp/security.htm

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ 1. Sambar Server 4.1 beta »ç¿ëÀÚµéÀº °¡´ÉÇϸé 4.1 production release·Î ¾÷±×·¹À̵åÇØ¾ß ÇÑ´Ù.
2. index.html³ª ȤÀº default.html°¡ ¾ø´Â µð·ºÅ丮¿¡¼­´Â µð·ºÅ丮 ºê¶ó¿ì¡À» Çã¿ëÇÏÁö ¸»¾Æ¾ß ÇÑ´Ù.
3. admin ÆÐ½º¿öµå°¡ ¼³Á¤ÀÌ ¾ÈµÇ¾î ÀÖ´Ù¸é Áï½Ã ¼³Á¤ÇÏ¿©¾ß ÇÑ´Ù.
4. Sambar ¼­¹ö¿¡ ¿¹Á¦ CGI ½ºÅ©¸³Æ®µéÀÌ ³²¾ÆÀÖ´Ù¸é ±× CGIµéÀÌ secureÇÏ´Ù´Â È®½ÅÀÌ µéÁö ¾Ê´Â´Ù¸é »èÁ¦ÇØ¾ß ÇÑ´Ù. ƯÈ÷ upload.pl¿Í dumpenv.plÀº ¹Ýµå½Ã »èÁ¦ÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)