English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22005
À§Çèµµ 30
Æ÷Æ® 80, ¡¦
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í Web Publishing ±â´ÉÀÌ ÀÛµ¿µÇ´Â Netscape Enterprise Server 3.x°ú 4.x ¹öÀüµéÀº Directory IndexingÀ̶ó ºÒ¸®´Â Ư¡À» °¡Áö°í ÀÖ´Ù. ÀÌ Æ¯Â¡Àº 'INDEX' Request¸¦ ÅëÇÏ¿© µð·ºÅ丮 ¸®½ºÆÃÀ» º¸¿©ÁÖ¸ç ¿ø°ÝÁöÀÇ Attacker°¡ À¥ µð·ºÅ丮³»¿¡ ÀÖ´Â (CGI ½ºÅ©¸³Æ®¿Í °°Àº) ÆÄÀϸíµéÀÇ ¸®½ºÆ®¸¦ °Ë»öÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
´ÙÀ½°ú °°Àº ¸í·É¿¡ ÀÇÇØ À¥¼­¹ö¿¡ ÀÖ´Â µð·ºÅ丮 ¸®½ºÆÃÀÌ °¡´ÉÇÏ´Ù.

INDEX / HTTP/1.0

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/5997.php
http://www.securityfocus.com/bid/2285
ÇØ°áÃ¥ Á¶Ä¡¹æ¹ýÀº Web Publishing ±â´ÉÀ» ¾ø¾Ö°Å³ª INDEX request¸¦ Disable ÇÏ´Â °Í(ÀÌ°Í ¶ÇÇÑ web publishing ±â´ÉÀ» ¾ø¾Ö´Â °ÍÀÌ´Ù.) ÀÌ´Ù.

°ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇÏ¿© Directory Indexing ±â´ÉÀ» ¾ø¾Ö±â À§Çؼ­´Â
1. °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ Open ÇÑ´Ù.
2. Content Management -> Document Preferences¸¦ Ŭ¸¯ÇÑ´Ù.
3. Directory IndexingÀ» NoneÀ¸·Î ¼ÂÇÑ´Ù.
°ü·Ã URL CVE-2001-0250 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)