English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 21779
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CGI
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö¿¡´Â Server Side Include °ø°Ý¿¡ Ãë¾àÇÑ CGI ÆÄÀÏÀÌ Á¸ÀçÇÑ´Ù. Server Side Include (SSI)´Â µ¿Àû À¥ ÆäÀÌÁöµéÀ» »ý¼ºÇϴµ¥ »ç¿ëµÈ´Ù. SSI´Â ÀáÀçÀûÀ¸·Î °³¹ßÀÚ¿¡ ÀÇÇØ ÀǵµµÇÁö ¾ÊÀº ¹æ¹ýµé·Î ¿î¿µÃ¼Á¦ÀÇ ¸í·ÉµéÀ» ½ÇÇàÇÏ´Â µ¥ µµ¿ëµÉ ¼ö ÀÖ´Ù. ¸¸¾à SSI ±â´ÉÀÌ »ç¿ëÇÔÀ¸·Î µÇ¾î ÀÖ´Ù¸é, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Server Side Includes (SSI)¸¦ ÀÌ¿ëÇÏ¿© ¼­¹ö¿¡ ÀÓÀÇÀÇ ½©(shell) ¸í·ÉµéÀ» Æ÷ÇÔÇÑ Àß Á¶ÀÛµÈ HTTP ¿äûÀ» º¸³» ¿µÇâÀ» ¹Þ´Â À¥ ¼­¹ö ÇÁ·Î¼¼¼­ÀÇ ±ÇÇÑÀ» °¡Áö°í ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ¸í·ÉµéÀ» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://support.microsoft.com/default.aspx?scid=kb;[LN];195291
http://support.microsoft.com/default.aspx?scid=kb;[LN];233969

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
¸ðµç HTTP ¼­¹ö ¸ðµç ¹öÀü
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ ½©(shell) ¸ÞŸ¹®ÀÚ(metacharater)µéÀ» ÇÊÅ͸µÇÏ¿© ½Ã½ºÅÛ ¸í·É ½ÇÇàÀÌ ¾ÈµÇµµ·Ï ¿µÇâÀ» ¹Þ´Â À¥ ÆäÀÌÁö¸¦ ¼öÁ¤ÇÏ¿©¾ß ÇÑ´Ù.

-- ȤÀº --

SSI°¡ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ¸ðµç µð·ºÅ丮µé¿¡ ´ëÇØ µðÆúÆ®·Î »ç¿ëÇÏÁö ¾ÊÀ½À¸·Î ¼³Á¤ÇÑ´Ù.

ApacheÀÇ °æ¿ì:
'Options Includes', 'Options IncludesNOEXEC' ȤÀº 'Options All' µîÀ» »ç¿ëÇÏÁö ¸»¾Æ¾ß ÇÑ´Ù. Àü¿ªÀûÀ¸·Î SSI¸¦ »ç¿ëÁßÁö Çϱâ À§Çؼ­´Â, ´ÙÀ½°ú °°ÀÌ Apache httpd.conf ±¸¼º ÆÄÀÏ¿¡ root µð·ºÅ丮¿¡ ´ëÇØ 'Options -Includes' ¿£Æ®¸®¸¦ Ãß°¡ÇØ ÁÖ¾î¾ß ÇÑ´Ù.

<Directory />
Options -Includes
</Directory>

Microsoft IISÀÇ °æ¿ì:
1. Regedit¸¦ ÀÌ¿ëÇÏ¿©, HKLM\System\CurrentControlSet\Services\W3SVC\Parameters ·¹Áö½ºÆ®¸® Å°¸¦ ã´Â´Ù.
2. SSIEnableCmdDirective·Î ¸í¸íµÈ ¿£Æ®¸®¸¦ ã´Â´Ù.
3. °ªÀ» 0À¸·Î º¯°æÇÑ´Ù.
°ü·Ã URL CVE-1999-0561 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 1268,13688 (ISS)