English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22012
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç MS Exchange Public Folders´Â ºñÀΰ¡µÈ »ç¿ëÀÚ¿¡°Ô ±Û·Î¹ú ÁÖ¼Ò ¸®½ºÆ®¸¦ º¸¿©ÁØ´Ù. Microsoft Exchange Public Folders´Â µðÆúÆ®·Î À͸íÀÇ Á¢¼ÓÀ» Çã¿ëÇØ ÁÖ°Ô µÇ¾î ÀÖ´Ù. À̰ÍÀÌ º¯°æµÇÁö ¾Ê¾Ò´Ù¸é Attacker´Â ÇØ´ç Exchange ¼­¹ö¿¡ ÀÖ´Â »ç¿ëÀڵ鿡 ´ëÇÑ (¸ðµç Email ÁÖ¼Ò, ÀüÈ­¹øÈ£ µî°ú °°Àº) Áß¿äÇÑ Á¤º¸¸¦ »©³»°¥ ¼ö ÀÖ´Ù.
ÀÌ Á¤º¸À¯Ãâ Ãë¾àÁ¡Àº Microsoft Outlook Web Access (OWA)¸¦ Á¦°øÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Â Exchange ¼­¹ö 5.5¿¡ Á¸ÀçÇÑ´Ù. ÀÌ ¹®Á¦´Â Global Address List¸¦ ÁúÀÇÇÏ´Â Microsoft Outlook Web Access (OWA)¿¡ ÀÖ´Â ÇÔ¼ö°¡ ÀÎÁõÀ» ÇÊ¿ä·Î ÇÏÁö ¾Ê±â ¶§¹®¿¡ ¹ß»ýÇÑ´Ù. ºñÀΰ¡µÈ »ç¿ëÀÚµéÀº ±× ÇÔ¼ö¸¦ È£ÃâÇÏ¿© ¼­¹ö¿¡ ÀÖ´Â »ç¿ëÀÚµéÀÇ ¸ÞÀÏ ÁÖ¼ÒµéÀ» ¿­°ÅÇØ º¼ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/windowsntfocus/5WP091P5FQ.html
http://www.microsoft.com/technet/security/bulletin/MS01-047.asp
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®·Î ºÎÅÍ ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ Patch¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù:
https://technet.microsoft.com/library/security/ms01-047
°ü·Ã URL CVE-2001-0660 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)