| Ãë¾àÁ¡ID |
21159 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
À¥¼¹ö¿¡ "/technote/main.cgi" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. TECH-NOTE´Â À¥ »çÀÌÆ®¸¦ À§ÇÑ Çѱ¹¾î °Ô½ÃÆÇ¿ë ¼ÒÇÁÆ®¿þ¾î ÀÌ´Ù. TECH-NOTE 2000¿¡´Â main.cgi ½ºÅ©¸³Æ®¿¡ Ãë¾àÁ¡ÀÌ ÀÖ¾î Attacker°¡ ¿ø°ÝÀ¸·Î À¥¼¹ö »ó¿¡ ÀÖ´Â µð·ºÅ丮µéÀ» µÚÁú ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. main.cgi ½ºÅ©¸³Æ®´Â open() ÇÔ¼ö¸¦ È£ÃâÇÒ ¶§ º¸¾È»ó ¹®Á¦¸¦ ÀÏÀ¸Å³ ¼ö ÀÖ´Â »ç¿ëÀÚ ÀÔ·Â ¹®ÀÚ¿À» °É·¯³»Áö ¸øÇÑ´Ù. Attacker´Â "dot dot" ½ÃÄö½º(/../)¸¦ Æ÷ÇÔÇÑ URLÀ» »ç¿ëÇÏ¿© À¥¼¹ö »óÀÇ ÀÓÀÇÀÇ µð·ºÅ丮³ª ÆÄÀϵéÀ» http µ¥¸óÀÇ ±ÇÇÑ(root ȤÀº nobody)À¸·Î Àо ¼ö ÀÖ´Ù. TECH-NOTE 2001µµ °°Àº Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ¹®Á¦¸¦ ÇØ°áÇÒ ¼ö ÀÖ´Â ¹æ¹ýÀº ³ª¿Í ÀÖÁö ¾Ê´Ù. ´ÙÀ½ »çÀÌÆ®¿¡¼ ÃֽйöÀüÀÇ Technote¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Ù. Http://www.technote.co.kr/php/technote1/board.php?board=consult&command=skin_insert&exe=insert_down_shop |
| °ü·Ã URL |
CVE-2001-0075 (CVE) |
| °ü·Ã URL |
2156 (SecurityFocus) |
| °ü·Ã URL |
5813 (ISS) |
|