| Ãë¾àÁ¡ID |
22019 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
Red Hat ¸®´ª½º 7.0¿¡ µþ·ÁÀÖ´Â ApacheÀÇ À¥¼¹öÀÇ ¹öÀüµé (ȤÀº ´Ù¸¥ Apache ¹èÆ÷ÆÇ)Àº ¿ÜºÎ »ç¿ëÀڵ鿡°Ô ÁÖ¾îÁø »ç¿ëÀÚ¸íÀÌ ½Ã½ºÅÛ »ó¿¡ Á¸ÀçÇÏ´ÂÁö¸¦ Å×½ºÆ®ÇØ º¼ ¼ö ÀÖµµ·Ï ÇØ ÁÖ´Â µðÆúÆ® ¼³Á¤¿À·ù°¡ Àִ ä·Î ¼³Ä¡µÈ´Ù. ¿¹¸¦µé¾î,
http://www.example.com/~<username>
»ç¿ëÀÚ°¡ ¿ø°ÝÀ¸·Î ÀÖÀ» ¼ö ÀÖ´Â »ç¿ëÀÚÀÇ µðÆúÆ® ÆäÀÌÁö¿¡ ´ëÇÑ ¿äûÀ» ÇÏ°Ô µÇ¸é ¼¹ö´Â ´ÙÀ½ ¼¼°¡Áö ÀÀ´ä ÁßÀÇ Çϳª¸¦ µ¹·ÁÁØ´Ù:
1. <username>ÀÌ Å¸´çÇÑ »ç¿ëÀÚ °èÁ¤À̰í ȨÆäÀÌÁö°¡ ¸¸µé¾îÁ® ÀÖ´Â °æ¿ì¶ó¸é ¼¹ö´Â »ç¿ëÀÚÀÇ È¨ÆäÀÌÁö¸¦ º¸¿©ÁØ´Ù. 2. <username>ÀÌ ¼¹ö¿¡ Á¸ÀçÇÏÁö¸¸ ȨÆäÀÌÁö ¹®¼°¡ ¸¸µé¾îÁ® ÀÖÁö ¾Ê´Ù¸é ¼¹ö´Â "You don't have permission to access /~username on this server" ¶ó´Â ¸Þ½ÃÁö¸¦ µ¹·ÁÁØ´Ù. 3. <username>ÀÌ ¼¹ö¿¡ °èÁ¤À¸·Î Á¸ÀçÇÏÁö ¾Ê´Â´Ù¸é Apache ¼¹öÀÇ ÀÀ´äÀº "The requested URL /~username was not found on this server" ¶ó´Â ¸Þ½ÃÁö¸¦ Æ÷ÇÔÇÑ´Ù.
¼¹ö°¡ ÈÄÀÚÀÇ µÎ °æ¿ìµé°ú °°ÀÌ ´Ù¸¥ ÀÀ´äÀ» º¸³¿À¸·Î½á ¿ÜºÎ »ç¿ëÀÚ´Â ÀÖÀ» ¼ö ÀÖ´Â »ç¿ëÀÚ¸íÀ» Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù. À̸¦ ÀÌ¿ëÇÏ¿© Ãë¾àÇÑ È£½ºÆ®¿¡ ´ëÇÑ Á» ´õ Á¤¹ÐÇÑ °ø°ÝÀÌ °¡´ÉÇØ Áú ¼ö ÀÖ´Ù. |
| ÇØ°áÃ¥ |
Á¶Ä¡¹æ¹ý1: µðÆúÆ®·Î ¼³Á¤µÈ UserDir directive¸¦ Disable ½ÃŲ´Ù. Á¶Ä¡¹æ¹ý2: httpd.conf¿¡¼ ÆÐ½º¸í¿¡ ´ëÇÑ URLÀ» º¯°æÇÑ´Ù.
% echo 'ErrorDocument 404 http://localhost/sample.html' >> /var/www/conf/httpd.conf % echo 'ErrorDocument 403 http://localhost/sample.html' >> /var/www/conf/httpd.conf % sudo apachectl restart |
| °ü·Ã URL |
CVE-2001-1013 (CVE) |
| °ü·Ã URL |
3335 (SecurityFocus) |
| °ü·Ã URL |
7129 (ISS) |
|