| Ãë¾àÁ¡ID |
22009 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ¡¦ |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
Netscape Enterprise ¼¹ö 3.x¿¡´Â Directory Indexing ȤÀº Web PublishingÀ̶ó ºÒ¸®´Â ±â´ÉÀ» °¡Áö°í ÀÖÀ¸¸ç µðÆúÆ®·Î Enable µÇ¾î ÀÖ´Ù. ÀÌ ±â´ÉÀº »ç¿ëÀÚ°¡ URL¿¡ ¾î¶² tag¸¦ Æ÷ÇÔÇÏ¿© ¿äûÀ» ÇÏ°Ô µÇ¸é µð·ºÅ丮¸¦ ¸®½ºÆÃÇØ ÁÖ´Â ¹ö±×¸¦ °¡Áö°í ÀÖ´Ù. À̰ÍÀº Attacker°¡ (CGI ½ºÅ©¸³Æ®¿Í °°Àº) ÆÄÀÏ ¸®½ºÆ®À» °Ë»öÇϰųª DocumentÀÇ ºÒ¹ýÀûÀÎ ¾×¼¼½º¸¦ Çã¿ëÇØ ÁÖ°Ô µÈ´Ù. ¿¹¸¦µé¾î,
http://home.netscape.com/?wp-cs-dump
¿Í °°ÀÌ ¿äû¿¡ À¥¼¹öÀÇ root µð·ºÅ丮¸¦ ¸®½ºÆÃÇØ ÁØ´Ù. ¶ÇÇÑ ÇÏÀ§ µð·ºÅ丮ÀÇ ³»¿ëµµ º¼ ¼ö ÀÖ´Ù. ÀÌ¿Í °°ÀÌ »ç¿ëµÇ¾î Áú ¼ö ÀÖ´Â ´Ù¸¥ ű׵鿡´Â ´ÙÀ½°ú °°Àº °ÍµéÀÌ ÀÖ´Ù.
?wp-ver-info ?wp-html-rend ?wp-usr-prop ?wp-ver-diff ?wp-verify-link ?wp-start-ver ?wp-stop-ver ?wp-uncheckout
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/4116.php http://home.netscape.com/enterprise/v3.6/index.html |
| ÇØ°áÃ¥ |
¹®Á¦ ÇØ°á ¹æ¹ý¿¡´Â ¸î°¡Áö°¡ ÀÖ´Ù. Netscape Enterprise Server (NES) 3.6sp3 ÀÌÇÏÀÇ ¹öÀü¿¡ °¡µ¿µÇ°í ÀÖ´Ù¸é "Directory Indexing"¸¦ Disable ÇÏ¿©¾ß ÇÑ´Ù (Áï, "None"À¸·Î ¼ÂÆÃÀ» ¹Ù²ã¾ß ÇÑ´Ù). ¸¸¾à iWS4.x ¼¹ö¶ó¸é "Directory Indexing"À» "None" À̳ª "Fancy"·Î ¹Ù²ã¾ß ÇÑ´Ù. °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇÏ¿© "Directory Indexing"À» ¹Ù²Ù±â À§Çؼ´Â 'Content Management'·Î °¡¼ 'Document Preferences' ¸¦ ¼±ÅÃÇÏ°í ¼¼°³ÀÇ Ã¼Å©¹Ú½ºµéÀ» ¼±ÅÃÇØ¾ß ÇÑ´Ù. ¸¸¾à Á÷Á¢ obj.conf ÆÄÀÏÀ» ¼öÁ¤ÇÏ°í ½Í´Ù¸é ´ÙÀ½°ú °°ÀÌ ÇØ´ç ¶óÀεéÀ» Á÷Á¢ ¼öÁ¤ÇØ¾ß ÇÑ´Ù.
("Simple" indexing) Service method=(GET|HEAD) type=magnus-internal/directory ·ç=index-simple
("Fancy" indexing) Service method=(GET|HEAD) type=magnus-internal/directory fn=index-common
Directory IndexingÀ» Disable Çϱâ À§Çؼ´Â À§¿¡ ³ªÅ¸³ ¶óÀεéÀ» °£´ÜÇÏ°Ô ÁÖ¼®Ã³¸® Çϰųª Á¦°ÅÇÒ ¼öµµ ÀÖ´Ù. |
| °ü·Ã URL |
CVE-2000-0236 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|