English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21772
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç Looking Glass´Â target Àμö¸¦ ÅëÇÑ ¸í·É ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Looking Glass´Â ping, traceroute, ±×¸®°í whois¿Í °°Àº ´Ù¾çÇÑ ³×Æ®¿öÅ© À¯Æ¿¸®Æ¼µé·ÎÀÇ CGI ½ºÅ©¸³Æ®·Î Á¦ÀÛµÈ À¥ ÀÎÅÍÆäÀ̽º¸¦ Á¦°øÇØ ÁØ´Ù. Looking Glass 20040427 ±×¸®°í 1.0 ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ Cross-Site Scripting °ø°Ý ¹× Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

1) footer.php ±×¸®°í header.php¿¡ ÀÖ´Â "version" ¹è¿­ Àμö·Î Àü´ÞµÈ ÀÔ·ÂÀº »ç¿ëÀڵ鿡°Ô ¹ÝȯµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ´Â ¿µÇâÀ» ¹Þ´Â »çÀÌÆ®¿¡¼­ »ç¿ëÀÚ ºê¶ó¿ìÀú ¼¼¼ÇÀ¸·Î ÀÓÀÇÀÇ HTML ¹× ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
2) lg.php¿¡ ÀÖ´Â "target" Àμö·Î Àü´ÞµÈ ÀÔ·ÂÀº "system()" È£Ãâ¿¡¼­ »ç¿ëµÇ¾î Áö±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ´Â "|" ÆÄÀÌÆ® ¹®ÀÚ µîÀ» ÅëÇØ ÀÓÀÇÀÇ ½©(shell) ¸í·ÉµéÀ» ÁÖÀÔÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2005-08/0381.html
http://secunia.com/advisories/16607/

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Intermedia Communications (formerly Digex), Looking Glass 20040427
Intermedia Communications (formerly Digex), Looking Glass 1.0
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ 2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.

¼Ò½º Äڵ带 ÆíÁýÇÏ¿© ÀÔ·ÂÀÌ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇµµ·Ï ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2005-2776,CVE-2005-2777 (CVE)
°ü·Ã URL 14680,14682 (SecurityFocus)
°ü·Ã URL 22044,22045 (ISS)