| Ãë¾àÁ¡ID |
21077 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ Webcom(www.webcom.se)ÀÇ CGI Guestbook(wguest.exe°ú rguest.exe ÆÄÀÏ)ÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÀÌ CGI´Â Attacker°¡ Anonymous Internet Account (IIS ¼¹öÀÇ IUSR_MACHINENAME) ¿Í NT¼¹ö³»ÀÇ NTFS read ±ÇÇÑÀÌ ÀÖ´Â ÀÓÀÇÀÇ ÅØ½ºÆ® ÆÄÀÏÀÇ Path¸¸ ¾È´Ù¸é ¿øÇÏ´Â ÅØ½ºÆ® ÆÄÀÏÀ» Àо ¼ö ÀÖ´Â ¹®Á¦Á¡ÀÌ ÀÖ´Ù. File Permission ü°è°¡ ¾ø´Â Windows 95/98¿¡¼´Â ¹°·Ð ¸ðµç ÅØ½ºÆ®À» Àо ¼ö ÀÖ´Ù.
¿¹¸¦µé¾î ´ÙÀ½°ú °°ÀÌ Çϸé
http://server/cgi-bin/wguest.exe?template=c:\boot.ini¿¡ ´ëÇÑ Request·Î´Â RemoteÀÇ À¥¼¹öÀÇ boot.ini ÆÄÀÏÀ» Àо ¼ö ÀÖ°í http://server/cgi-bin/rguest.exe?template=c:\winnt\system32\$winnt$.inf
¶ó´Â Request¸¦ ÁÖ¸é $winnt$.inf ÆÄÀÏÀ» Àо ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
ÀÌ·¯ÇÑ ¹®Á¦°¡ ÇØ°áµÈ ¾÷µ¥ÀÌÆ® ¹öÀüÀ» ±¸ÇÒ ¶§±îÁö À¥¼¹ö·Î ºÎÅÍ WebCom Guestbook CGI ÄÄÆ÷³ÍÆ®µéÀ» Á¦°ÅÇØ µÎ¾î¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0467 (CVE) |
| °ü·Ã URL |
2024 (SecurityFocus) |
| °ü·Ã URL |
2072 (ISS) |
|