English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22009
À§Çèµµ 30
Æ÷Æ® 80, ¡¦
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í Netscape Enterprise ¼­¹ö 3.x¿¡´Â Directory Indexing ȤÀº Web PublishingÀ̶ó ºÒ¸®´Â ±â´ÉÀ» °¡Áö°í ÀÖÀ¸¸ç µðÆúÆ®·Î Enable µÇ¾î ÀÖ´Ù. ÀÌ ±â´ÉÀº »ç¿ëÀÚ°¡ URL¿¡ ¾î¶² tag¸¦ Æ÷ÇÔÇÏ¿© ¿äûÀ» ÇÏ°Ô µÇ¸é µð·ºÅ丮¸¦ ¸®½ºÆÃÇØ ÁÖ´Â ¹ö±×¸¦ °¡Áö°í ÀÖ´Ù. À̰ÍÀº Attacker°¡ (CGI ½ºÅ©¸³Æ®¿Í °°Àº) ÆÄÀÏ ¸®½ºÆ®À» °Ë»öÇϰųª DocumentÀÇ ºÒ¹ýÀûÀÎ ¾×¼¼½º¸¦ Çã¿ëÇØ ÁÖ°Ô µÈ´Ù. ¿¹¸¦µé¾î,

http://home.netscape.com/?wp-cs-dump

¿Í °°ÀÌ ¿äû¿¡ À¥¼­¹öÀÇ root µð·ºÅ丮¸¦ ¸®½ºÆÃÇØ ÁØ´Ù. ¶ÇÇÑ ÇÏÀ§ µð·ºÅ丮ÀÇ ³»¿ëµµ º¼ ¼ö ÀÖ´Ù. ÀÌ¿Í °°ÀÌ »ç¿ëµÇ¾î Áú ¼ö ÀÖ´Â ´Ù¸¥ ű׵鿡´Â ´ÙÀ½°ú °°Àº °ÍµéÀÌ ÀÖ´Ù.

?wp-ver-info
?wp-html-rend
?wp-usr-prop
?wp-ver-diff
?wp-verify-link
?wp-start-ver
?wp-stop-ver
?wp-uncheckout

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/4116.php
http://home.netscape.com/enterprise/v3.6/index.html
ÇØ°áÃ¥ ¹®Á¦ ÇØ°á ¹æ¹ý¿¡´Â ¸î°¡Áö°¡ ÀÖ´Ù.
Netscape Enterprise Server (NES) 3.6sp3 ÀÌÇÏÀÇ ¹öÀü¿¡ °¡µ¿µÇ°í ÀÖ´Ù¸é "Directory Indexing"¸¦ Disable ÇÏ¿©¾ß ÇÑ´Ù (Áï, "None"À¸·Î ¼ÂÆÃÀ» ¹Ù²ã¾ß ÇÑ´Ù). ¸¸¾à iWS4.x ¼­¹ö¶ó¸é "Directory Indexing"À» "None" À̳ª "Fancy"·Î ¹Ù²ã¾ß ÇÑ´Ù.
°ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇÏ¿© "Directory Indexing"À» ¹Ù²Ù±â À§Çؼ­´Â 'Content Management'·Î °¡¼­ 'Document Preferences' ¸¦ ¼±ÅÃÇÏ°í ¼¼°³ÀÇ Ã¼Å©¹Ú½ºµéÀ» ¼±ÅÃÇØ¾ß ÇÑ´Ù.
¸¸¾à Á÷Á¢ obj.conf ÆÄÀÏÀ» ¼öÁ¤ÇÏ°í ½Í´Ù¸é ´ÙÀ½°ú °°ÀÌ ÇØ´ç ¶óÀεéÀ» Á÷Á¢ ¼öÁ¤ÇØ¾ß ÇÑ´Ù.

("Simple" indexing)
Service method=(GET|HEAD) type=magnus-internal/directory ·ç=index-simple

("Fancy" indexing)
Service method=(GET|HEAD) type=magnus-internal/directory fn=index-common

Directory IndexingÀ» Disable Çϱâ À§Çؼ­´Â À§¿¡ ³ªÅ¸³­ ¶óÀεéÀ» °£´ÜÇÏ°Ô ÁÖ¼®Ã³¸® Çϰųª Á¦°ÅÇÒ ¼öµµ ÀÖ´Ù.
°ü·Ã URL CVE-2000-0236 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)