English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21194
À§Çèµµ 30
Æ÷Æ® 80, ¡¦
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í À¥¼­¹ö¿¡ "ustorekeeper.pl" CGI°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. uStorekeeper´Â ¿Â¶óÀÎ »óÁ¡À» »ý¼ºÇϰí ÀÛµ¿½Ãų ¼ö ÀÖÀ¸¸ç °ü¸®±îÁö °¡´ÉÇÑ ¿ÏÀüÇÑ ÀüÀÚ»ó°Å·¡ ¼Ö·ç¼ÇÀÌ´Ù.
Ustorekeeper.pl ½ºÅ©¸³Æ®¿¡´Â "command" Àμö¸¦ ÅëÇÏ¿© ustorekeeper.pl¿¡ °Ç³×Áø °ª¿¡ ´ëÇÑ ºÒÃæºÐÇÑ Ã¼Å©·Î ÀÎÇÏ¿© À¥¼­¹ö»óÀÇ ¸ðµç µð·ºÅ丮°¡ °Ë»öµÇ¾îÁú ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ ÀÖ´Ù. Attacker´Â "dot dot" ½ÃÄö½º(/../)¸¦ Æ÷ÇÔÇÏ´Â URLÀ» »ç¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ÀÌ¹Ì ÀÎÁöÇϰí ÀÖ´Â ½Ã½ºÅÛ »óÀÇ ÀÓÀÇÀÇ ÆÄÀϰú µð·ºÅ丮µéÀÇ ³»¿ëÀ» http µ¥¸óÀÇ ±ÇÇÑ(root ȤÀº nobody)À¸·Î º¼ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.uburst.com/uStorekeeper/index.html
http://www.securiteam.com/securitynews/5MP051P4AQ.html
http://online.securityfocus.com/bid/2536

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ /cgi-bin µð·ºÅ丮¿¡¼­ 'ustorekeeper.pl' ÆÄÀÏÀ» »èÁ¦ÇÏ¿©¾ß ÇÑ´Ù. ¾Æ´Ï¸é ¹®Á¦°¡ ¾ø´Â ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)