English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21211
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç 'MRTG(Multi Router Traffic Grapher)' CGI ´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
MRTG´Â ³×Æ®¿öÅ© ¸µÅ© »ó¿¡ Æ®·¡ÇÈÀ» ¸ð´ÏÅ͸µÇÏ´Â Åø·Î½á ³×Æ®¿öÅ© Æ®·¡ÇÈÀ» °¡½ÃÀûÀ¸·Î Ç¥ÇöÇØ ÁÖ´Â ±×·¡ÇÈ À̹ÌÁöµéÀ» Æ÷ÇÔÇÑ HTML ¹®¼­¸¦ ¸¸µé¾î ³½´Ù. 'MRTG' CGI ½ºÅ©¸³Æ®µé (ÇöÀç ¹öÀüÀº 2.9.17ÀÌ´Ù)Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀԷ Ÿ´ç¼º °Ë»çÀÇ ¿¡·¯·Î ÀÎÇÏ¿© http µ¥¸óÀÇ ±ÇÇÑÀ¸·Î À¥¼­¹ö »óÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» Àо ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.
Ãë¾àÇÏ´Ù°í ¾Ë·ÁÁø ½ºÅ©¸³Æ®µéÀº mrtg.cgi, traffic.cgi, 14all-1.1.cgi, 14all.cgi ÀÌ´Ù. Ãë¾àÇÑ ¸ðµç ½ºÅ©¸³µéÀº µ¿ÀÏÇÑ ÁúÀÇ ¹®Àå("cfg="Àº º¯¼ö)À¸·Î µµ¿ëµÉ ¼ö ÀÖ´Ù.

* ¿¹Á¦ URLµé:
http://somehost/mrtg.cgi?cfg=../../../../../../../../etc/passwd
http://www.target.com/cgi-bin/14all.cgi?cfg=../../../../../../../../etc/passwd
http://www.target.com/cgi-bin/14all-1.1.cgi?cfg=../../../../../../../../etc/passwd
http://www.target.com/cgi-bin/traffic.cgi?cfg=../../../../../../../../etc/passwd

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Web Server
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ÇØ°á¹æ¹ýÀº ³ª¿ÍÀÖÁö ¾Ê´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á cfg Àμöµé·ÎºÎÅÍ Àǽɽº·¯¿î ¹®ÀÚµéÀ» °É·¯³»±â À§ÇØ ´ÙÀ½ ¶óÀÎÀ» Ãë¾àÇÑ ½ºÅ©¸³Æ®µé¿¡ Ãß°¡ÇØ¾ß ÇÑ´Ù:
$input =~s/[(\.\.)|\/]//g;
°ü·Ã URL CVE-2002-0232 (CVE)
°ü·Ã URL 4017 (SecurityFocus)
°ü·Ã URL 8062 (ISS)