English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21075
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í AltaVista °Ë»ö ¼ÒÇÁÆ®¿þ¾î¿¡ ÀÖ´Â query CGI ÇÁ·Î±×·¥Àº ´ÙÀ½°ú °°ÀÌ mssÀÇ Àμö¿¡ "../" ȤÀº "%2e%2e/"¸¦ ÀÔ·ÂÇÔÀ¸·Î½á ÆÄÀϽýºÅÛ »óÀÇ ÇѼöÁØ À§ÀÇ ÆÄÀϵéÀÇ ³»¿ëÀ» º¼ ¼ö ÀÖ´Ù.

GET /cgi-bin/query?mss=%2e%2e/config

À̰ÍÀº ¸Å¿ì Áß¿äÇÑ Á¤º¸¸¦ °¡Áö°í ÀÖ´Â AltaVista Search ¼³Á¤ ÆÄÀÏ¿¡ ´ëÇÑ ¿ÜºÎ·Î ºÎÅÍÀÇ °Ë»öÀ» Çã¿ëÇÏ¸ç ³ª¾Æ°¡ 16Áø Ç¥Çö½ÄÀ» ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ ³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» º¼ ¼öµµ ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº AltaVista Search 2.x¿¡ ³²¾Æ ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ 1. <install-dir>/httpd/config ÆÄÀÏÀ» ÆíÁýÇÏ¿© MGMT_IPSPEC¸¦ ¼öÁ¤ÇÏ¿© "0.0.0.0/0"¸¦ "127.0.0.1/32"¿Í °°Àº Ưº°ÇÑ IP·Î ¼³Á¤ÇÑ´Ù.
2. °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ ÆäÀÌÁö gatheringÀ» ÁßÁöÇÑ´Ù.
3. altavista °Ë»ö ¼­ºñ½º¸¦ Àç°¡µ¿ÇÑ´Ù. (¼³Á¤ ÆÄÀÏÀÌ ´Ù½Ã ÀÐÇôÁ®¾ß ÇÔ)
4. ÇÊ¿äÇÏ´Ù¸é ÆäÀÌÁö gatheringÀ» Àç°¡µ¿ÇÑ´Ù.
5. °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ »ç¿ëÀÚ¸í/ÆÐ½º¿öµå¸¦ Àӽ÷Π»ç¿ëÇÒ ¼ö ÀÖ´Â °ÍÀ¸·Î Àá½Ã º¯°æÇÑ´Ù.
6. ../logs/mgtstate ¸¦ ´Ù¿î·Îµå ¹Þ¾Æ º»´Ù. (cache¿¡ ³²°ÜµÎ±â À§ÇÔ)
http://localhost:9000/cgi-bin/query?mss=../logs/mgtstate
7. °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ »ç¿ëÀÚ¸í/ÆÐ½º¿öµå¸¦ ÃßÃøÇϱ⠾î·Á¿î °ÍÀ¸·Î º¯°æÇÑ´Ù.
8. AltaVista ¼­ºñ½º¸¦ Àç°¡µ¿Çϰųª cache¸¦ Áö¿ìÁö ¸»°í ±×´ë·Î ³öµÎ¸é µÈ´Ù.
°ü·Ã URL CVE-2000-0039 (CVE)
°ü·Ã URL 896 (SecurityFocus)
°ü·Ã URL 3754 (ISS)