English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21111
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ IIS¼­¹öÀÇ PHP/FI ÆÐŰÁö¿¡ µþ·Á³ª¿À´Â »ùÇà ½ºÅ©¸³Æ®ÀÎ 'mylog.html' ÆÄÀÏÀÌ Á¸ÀçÇÑ´Ù. ÀÌ ÆÄÀÏÀº ¿ÜºÎ¿¡¼­ ¼­¹ö³»ÀÇ httpd µ¥¸óÀÇ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ÆÄÀÏÀ» Àо ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ´ÙÀ½°ú °°ÀÌ Çϸé Ãë¾àÁ¡ ¿©ºÎ¸¦ ¾Ë ¼ö ÀÖ´Ù.

¡Ø È®Àιæ¹ý : http://www.victim.com/cool-logs/mylog.html?screen=C:\config.sys

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft IIS Server
ÇØ°áÃ¥ 1. /cool-logs³» mlog.html ÆÄÀÏÀ» Á¦°ÅÇϰí PHP web site (www.php.net)¿¡¼­ Patch¸¦ ¹Þ¾Æ ¼³Ä¡ÇÑ´Ù.

2. Fix : '<?include...' ¶óÀÎ ¾Õ¿¡ ´ÙÀ½ ¶óÀÎÀ» Ãß°¡ÇÑ´Ù.
<?ereg_replace("/","",$screen);>
°ü·Ã URL CVE-1999-0068 (CVE)
°ü·Ã URL 713 (SecurityFocus)
°ü·Ã URL 1468 (ISS)