| Ãë¾àÁ¡ID |
21111 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç À¥¼¹ö¿¡ IIS¼¹öÀÇ PHP/FI ÆÐŰÁö¿¡ µþ·Á³ª¿À´Â »ùÇà ½ºÅ©¸³Æ®ÀÎ 'mylog.html' ÆÄÀÏÀÌ Á¸ÀçÇÑ´Ù. ÀÌ ÆÄÀÏÀº ¿ÜºÎ¿¡¼ ¼¹ö³»ÀÇ httpd µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ÆÄÀÏÀ» Àо ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ´ÙÀ½°ú °°ÀÌ Çϸé Ãë¾àÁ¡ ¿©ºÎ¸¦ ¾Ë ¼ö ÀÖ´Ù.
¡Ø È®Àιæ¹ý : http://www.victim.com/cool-logs/mylog.html?screen=C:\config.sys
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: * ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft IIS Server |
| ÇØ°áÃ¥ |
1. /cool-logs³» mlog.html ÆÄÀÏÀ» Á¦°ÅÇϰí PHP web site (www.php.net)¿¡¼ Patch¸¦ ¹Þ¾Æ ¼³Ä¡ÇÑ´Ù.
2. Fix : '<?include...' ¶óÀÎ ¾Õ¿¡ ´ÙÀ½ ¶óÀÎÀ» Ãß°¡ÇÑ´Ù. <?ereg_replace("/","",$screen);> |
| °ü·Ã URL |
CVE-1999-0068 (CVE) |
| °ü·Ã URL |
713 (SecurityFocus) |
| °ü·Ã URL |
1468 (ISS) |
|