English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22019
À§Çèµµ 20
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í Red Hat ¸®´ª½º 7.0¿¡ µþ·ÁÀÖ´Â ApacheÀÇ À¥¼­¹öÀÇ ¹öÀüµé (ȤÀº ´Ù¸¥ Apache ¹èÆ÷ÆÇ)Àº ¿ÜºÎ »ç¿ëÀڵ鿡°Ô ÁÖ¾îÁø »ç¿ëÀÚ¸íÀÌ ½Ã½ºÅÛ »ó¿¡ Á¸ÀçÇÏ´ÂÁö¸¦ Å×½ºÆ®ÇØ º¼ ¼ö ÀÖµµ·Ï ÇØ ÁÖ´Â µðÆúÆ® ¼³Á¤¿À·ù°¡ Àִ ä·Î ¼³Ä¡µÈ´Ù. ¿¹¸¦µé¾î,

http://www.example.com/~<username>

»ç¿ëÀÚ°¡ ¿ø°ÝÀ¸·Î ÀÖÀ» ¼ö ÀÖ´Â »ç¿ëÀÚÀÇ µðÆúÆ® ÆäÀÌÁö¿¡ ´ëÇÑ ¿äûÀ» ÇÏ°Ô µÇ¸é ¼­¹ö´Â ´ÙÀ½ ¼¼°¡Áö ÀÀ´ä ÁßÀÇ Çϳª¸¦ µ¹·ÁÁØ´Ù:

1. <username>ÀÌ Å¸´çÇÑ »ç¿ëÀÚ °èÁ¤À̰í ȨÆäÀÌÁö°¡ ¸¸µé¾îÁ® ÀÖ´Â °æ¿ì¶ó¸é ¼­¹ö´Â »ç¿ëÀÚÀÇ È¨ÆäÀÌÁö¸¦ º¸¿©ÁØ´Ù.
2. <username>ÀÌ ¼­¹ö¿¡ Á¸ÀçÇÏÁö¸¸ ȨÆäÀÌÁö ¹®¼­°¡ ¸¸µé¾îÁ® ÀÖÁö ¾Ê´Ù¸é ¼­¹ö´Â "You don't have permission to access /~username on this server" ¶ó´Â ¸Þ½ÃÁö¸¦ µ¹·ÁÁØ´Ù.
3. <username>ÀÌ ¼­¹ö¿¡ °èÁ¤À¸·Î Á¸ÀçÇÏÁö ¾Ê´Â´Ù¸é Apache ¼­¹öÀÇ ÀÀ´äÀº "The requested URL /~username was not found on this server" ¶ó´Â ¸Þ½ÃÁö¸¦ Æ÷ÇÔÇÑ´Ù.

¼­¹ö°¡ ÈÄÀÚÀÇ µÎ °æ¿ìµé°ú °°ÀÌ ´Ù¸¥ ÀÀ´äÀ» º¸³¿À¸·Î½á ¿ÜºÎ »ç¿ëÀÚ´Â ÀÖÀ» ¼ö ÀÖ´Â »ç¿ëÀÚ¸íÀ» Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù. À̸¦ ÀÌ¿ëÇÏ¿© Ãë¾àÇÑ È£½ºÆ®¿¡ ´ëÇÑ Á» ´õ Á¤¹ÐÇÑ °ø°ÝÀÌ °¡´ÉÇØ Áú ¼ö ÀÖ´Ù.
ÇØ°áÃ¥ Á¶Ä¡¹æ¹ý1: µðÆúÆ®·Î ¼³Á¤µÈ UserDir directive¸¦ Disable ½ÃŲ´Ù.
Á¶Ä¡¹æ¹ý2:
httpd.conf¿¡¼­ ÆÐ½º¸í¿¡ ´ëÇÑ URLÀ» º¯°æÇÑ´Ù.

% echo 'ErrorDocument 404 http://localhost/sample.html' >> /var/www/conf/httpd.conf
% echo 'ErrorDocument 403 http://localhost/sample.html' >> /var/www/conf/httpd.conf
% sudo apachectl restart
°ü·Ã URL CVE-2001-1013 (CVE)
°ü·Ã URL 3335 (SecurityFocus)
°ü·Ã URL 7129 (ISS)