English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21140
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥¼­¹ö¿¡ MicrosoftÀÇ FrontPage 97 and 98 Server Extensions¿¡ Æ÷ÇÔµÇ¾î ³ª¿À´Â fpcount.exe ÆÄÀÏÀÌ Á¸ÀçÇÑ´Ù.
ÀÌ ÇÁ·Î±×·¥Àº À¥ Hit Ä«¿îÅͷμ­ »ç¿ëµÇ´Âµ¥ ÀÌ ÇÁ·Î±×·¥ÀÌ ¿ÜºÎ »ç¿ëÀÚ¿¡ ÀÇÇØ Á÷Á¢ÀûÀ¸·Î ¾×¼¼½ºµÈ´Ù¸é Buffer Overflow¸¦ À¯¹ß½Ãų ¼ö ÀÖÀ¸¸ç ÀÌ °á°ú·Î ÇÁ·Î¼¼¼­°¡ 100 %·Î °¡µ¿À²ÀÌ ¿Ã¶ó°¡¸é¼­ ¼­ºñ½º°ÅºÎ°ø°Ý(DoS) °ø°ÝÀ» ´çÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
ÀÌ DoS °ø°ÝÀº ´ÙÀ½°ú °°Àº µÎ°¡Áö Request¸¦ º¸³¿À¸·Î½á °¡´ÉÇÏ´Ù.

1) http://www.server.com/scripts/fpcount.exe?Page=default.htm|Image=3|Digits=10000
2) http://www.server.com/scripts/fpcount.exe?Page=default.htm|Image=3|Digits=-10000

¡Ø FrontPage 2000 Server Extentions¿¡´Â ÀÌ ¹®Á¦°¡ Á¸ÀçÇÏÁö ¾Ê´Â´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
MicrosoftÀÇ FrontPage 97 and 98 Server Extensions
ÇØ°áÃ¥ 1. PatchµÈ ÇÁ·Î±×·¥À¸·Î ´ëüÇϱâ Àü±îÁö CGI¸¦ Á¦°ÅÇØ ³õ´Â´Ù.
2. FrontPage 98ÀÇ °æ¿ì 98b Patch¸¦ Àû¿ëÇÑ´Ù. (Reference Site Âü°í)
°ü·Ã URL CVE-1999-1376 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 5494 (ISS)