English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22024
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Apache HTTP ¼­¹ö (win32)´Â ¿ø°ÝÁöÀÇ »ç¿ëÀڵ鿡°Ô µð·ºÅ丮 ¸®½ºÆÃÀ» Çã¿ëÇϸç HTTP µð·ºÅ丮³ª ÇÏÀ§ µð·ºÅ丮¿¡ ÀÖ´Â ÆÄÀÏÀ̳ª ½ºÅ©¸³Æ®µéÀ» »ìÆìº¼ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. ÀÏÁ¤ ¼öÀÇ ½½·¡½¬(/)·Î GET ¿äûÀ» º¸³¿À¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â µð·ºÅ丮 ¸®½ºÆÃÀ» ¾òÀ» ¼ö ÀÖÀ¸¸ç ±× µð·ºÅ丮¿Í ÇÏÀ§ µð·ºÅ丮¿¡ ÀÖ´Â ÆÄÀÏÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ´Ù. ÀÌ °ø°Ý¿¡ »ç¿ëµÇ´Â ½½·¡½¬ÀÇ ¼ö´Â ¼­¹ö¸¶´Ù ´Ù¸£´Ù. "/"ÀÇ °¹¼ö´Â DocumentRoot·ÎÀÇ °æ·Î¸í(path)ÀÇ ±æÀÌ¿Í °ü°èÀÖ´Ù.

Ãë¾àÇÑ Ç÷§Æû:
Apache HTTP Server 1.3.x win32
IBM HTTP Server 1.3.3 win32
IBM HTTP Server 1.3.6.2 win32

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/1284
httphttp://www.iss.net/security_center/static/4575.php
ÇØ°áÃ¥ Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î½á "Indexes" ¿É¼ÇÀ» ÀÛµ¿ÁßÁö(Disable)½Ãų ¼ö ÀÖ´Ù.

-- ȤÀº --

www.apache.org¿¡¼­ Àû¾îµµ Apache ¹öÀü 1.3.14³ª ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2000-0505 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)