| Ãë¾àÁ¡ID |
21075 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
AltaVista °Ë»ö ¼ÒÇÁÆ®¿þ¾î¿¡ ÀÖ´Â query CGI ÇÁ·Î±×·¥Àº ´ÙÀ½°ú °°ÀÌ mssÀÇ Àμö¿¡ "../" ȤÀº "%2e%2e/"¸¦ ÀÔ·ÂÇÔÀ¸·Î½á ÆÄÀϽýºÅÛ »óÀÇ ÇѼöÁØ À§ÀÇ ÆÄÀϵéÀÇ ³»¿ëÀ» º¼ ¼ö ÀÖ´Ù.
GET /cgi-bin/query?mss=%2e%2e/config
À̰ÍÀº ¸Å¿ì Áß¿äÇÑ Á¤º¸¸¦ °¡Áö°í ÀÖ´Â AltaVista Search ¼³Á¤ ÆÄÀÏ¿¡ ´ëÇÑ ¿ÜºÎ·Î ºÎÅÍÀÇ °Ë»öÀ» Çã¿ëÇÏ¸ç ³ª¾Æ°¡ 16Áø Ç¥Çö½ÄÀ» ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ ³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» º¼ ¼öµµ ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº AltaVista Search 2.x¿¡ ³²¾Æ ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
1. <install-dir>/httpd/config ÆÄÀÏÀ» ÆíÁýÇÏ¿© MGMT_IPSPEC¸¦ ¼öÁ¤ÇÏ¿© "0.0.0.0/0"¸¦ "127.0.0.1/32"¿Í °°Àº Ưº°ÇÑ IP·Î ¼³Á¤ÇÑ´Ù. 2. °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ ÆäÀÌÁö gatheringÀ» ÁßÁöÇÑ´Ù. 3. altavista °Ë»ö ¼ºñ½º¸¦ Àç°¡µ¿ÇÑ´Ù. (¼³Á¤ ÆÄÀÏÀÌ ´Ù½Ã ÀÐÇôÁ®¾ß ÇÔ) 4. ÇÊ¿äÇÏ´Ù¸é ÆäÀÌÁö gatheringÀ» Àç°¡µ¿ÇÑ´Ù. 5. °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ »ç¿ëÀÚ¸í/ÆÐ½º¿öµå¸¦ Àӽ÷Π»ç¿ëÇÒ ¼ö ÀÖ´Â °ÍÀ¸·Î Àá½Ã º¯°æÇÑ´Ù. 6. ../logs/mgtstate ¸¦ ´Ù¿î·Îµå ¹Þ¾Æ º»´Ù. (cache¿¡ ³²°ÜµÎ±â À§ÇÔ) http://localhost:9000/cgi-bin/query?mss=../logs/mgtstate 7. °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ »ç¿ëÀÚ¸í/ÆÐ½º¿öµå¸¦ ÃßÃøÇϱ⠾î·Á¿î °ÍÀ¸·Î º¯°æÇÑ´Ù. 8. AltaVista ¼ºñ½º¸¦ Àç°¡µ¿Çϰųª cache¸¦ Áö¿ìÁö ¸»°í ±×´ë·Î ³öµÎ¸é µÈ´Ù. |
| °ü·Ã URL |
CVE-2000-0039 (CVE) |
| °ü·Ã URL |
896 (SecurityFocus) |
| °ü·Ã URL |
3754 (ISS) |
|