Ãë¾àÁ¡ID |
21772 |
À§Çèµµ |
40 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
CGI |
»ó¼¼¼³¸í |
ÇØ´ç Looking Glass´Â target Àμö¸¦ ÅëÇÑ ¸í·É ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Looking Glass´Â ping, traceroute, ±×¸®°í whois¿Í °°Àº ´Ù¾çÇÑ ³×Æ®¿öÅ© À¯Æ¿¸®Æ¼µé·ÎÀÇ CGI ½ºÅ©¸³Æ®·Î Á¦ÀÛµÈ À¥ ÀÎÅÍÆäÀ̽º¸¦ Á¦°øÇØ ÁØ´Ù. Looking Glass 20040427 ±×¸®°í 1.0 ¹öÀüµéÀº ´ÙÁßÀÇ Ãë¾àÁ¡µé¿¡ Ãë¾àÇÏ´Ù. ÀÌ Ãë¾àÁ¡µéÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ Cross-Site Scripting °ø°Ý ¹× Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
1) footer.php ±×¸®°í header.php¿¡ ÀÖ´Â "version" ¹è¿ Àμö·Î Àü´ÞµÈ ÀÔ·ÂÀº »ç¿ëÀڵ鿡°Ô ¹ÝȯµÇ±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ´Â ¿µÇâÀ» ¹Þ´Â »çÀÌÆ®¿¡¼ »ç¿ëÀÚ ºê¶ó¿ìÀú ¼¼¼ÇÀ¸·Î ÀÓÀÇÀÇ HTML ¹× ½ºÅ©¸³Æ® Äڵ带 ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. 2) lg.php¿¡ ÀÖ´Â "target" Àμö·Î Àü´ÞµÈ ÀÔ·ÂÀº "system()" È£Ãâ¿¡¼ »ç¿ëµÇ¾î Áö±â Àü¿¡ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇÁö ¾Ê´Â´Ù. ÀÌ´Â "|" ÆÄÀÌÆ® ¹®ÀÚ µîÀ» ÅëÇØ ÀÓÀÇÀÇ ½©(shell) ¸í·ÉµéÀ» ÁÖÀÔÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2005-08/0381.html http://secunia.com/advisories/16607/
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Intermedia Communications (formerly Digex), Looking Glass 20040427 Intermedia Communications (formerly Digex), Looking Glass 1.0 ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
2014³â 6¿ù ÇöÀç ¾÷±×·¹À̵峪 ÆÐÄ¡´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.
¼Ò½º Äڵ带 ÆíÁýÇÏ¿© ÀÔ·ÂÀÌ ÀûÀýÇÏ°Ô ÇÊÅ͸µµÇµµ·Ï ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2005-2776,CVE-2005-2777 (CVE) |
°ü·Ã URL |
14680,14682 (SecurityFocus) |
°ü·Ã URL |
22044,22045 (ISS) |
|