| Ãë¾àÁ¡ID |
21211 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
CGI |
| »ó¼¼¼³¸í |
ÇØ´ç 'MRTG(Multi Router Traffic Grapher)' CGI ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. MRTG´Â ³×Æ®¿öÅ© ¸µÅ© »ó¿¡ Æ®·¡ÇÈÀ» ¸ð´ÏÅ͸µÇÏ´Â Åø·Î½á ³×Æ®¿öÅ© Æ®·¡ÇÈÀ» °¡½ÃÀûÀ¸·Î Ç¥ÇöÇØ ÁÖ´Â ±×·¡ÇÈ À̹ÌÁöµéÀ» Æ÷ÇÔÇÑ HTML ¹®¼¸¦ ¸¸µé¾î ³½´Ù. 'MRTG' CGI ½ºÅ©¸³Æ®µé (ÇöÀç ¹öÀüÀº 2.9.17ÀÌ´Ù)Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀԷ Ÿ´ç¼º °Ë»çÀÇ ¿¡·¯·Î ÀÎÇÏ¿© http µ¥¸óÀÇ ±ÇÇÑÀ¸·Î À¥¼¹ö »óÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» Àо ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. Ãë¾àÇÏ´Ù°í ¾Ë·ÁÁø ½ºÅ©¸³Æ®µéÀº mrtg.cgi, traffic.cgi, 14all-1.1.cgi, 14all.cgi ÀÌ´Ù. Ãë¾àÇÑ ¸ðµç ½ºÅ©¸³µéÀº µ¿ÀÏÇÑ ÁúÀÇ ¹®Àå("cfg="Àº º¯¼ö)À¸·Î µµ¿ëµÉ ¼ö ÀÖ´Ù.
* ¿¹Á¦ URLµé: http://somehost/mrtg.cgi?cfg=../../../../../../../../etc/passwd http://www.target.com/cgi-bin/14all.cgi?cfg=../../../../../../../../etc/passwd http://www.target.com/cgi-bin/14all-1.1.cgi?cfg=../../../../../../../../etc/passwd http://www.target.com/cgi-bin/traffic.cgi?cfg=../../../../../../../../etc/passwd
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Web Server |
| ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ÇØ°á¹æ¹ýÀº ³ª¿ÍÀÖÁö ¾Ê´Ù.
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á cfg Àμöµé·ÎºÎÅÍ Àǽɽº·¯¿î ¹®ÀÚµéÀ» °É·¯³»±â À§ÇØ ´ÙÀ½ ¶óÀÎÀ» Ãë¾àÇÑ ½ºÅ©¸³Æ®µé¿¡ Ãß°¡ÇØ¾ß ÇÑ´Ù: $input =~s/[(\.\.)|\/]//g; |
| °ü·Ã URL |
CVE-2002-0232 (CVE) |
| °ü·Ã URL |
4017 (SecurityFocus) |
| °ü·Ã URL |
8062 (ISS) |
|