English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22045
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Oracle 9i Application ¼­¹ö¿¡ ÀÖ´Â PL/SQL °ü¸® ÆäÀÌÁö´Â ÀÎÁõÀýÂ÷¸¦ °ÅÄ¡Áö ¾Ê´Â´Ù. Oracle 9iAS¸¦ µðÆúÆ®·Î ¼³Ä¡ÇßÀ» ¶§, mod_plsql DAD Admin ÀÎÅÍÆäÀ̽º¿¡ ´ëÇÑ ¾×¼¼½º°¡ °¡´ÉÇÏ¿© ¾Æ¹«³ª ÀÎÁõ¾øÀÌ ¿ø°ÝÀ¸·Î PL/SQL DADµéÀ» °ü¸®ÇÏ´Â °ÍÀÌ °¡´ÉÇÏ´Ù.
À̰ÍÀº °ø°ÝÀÚ°¡ ¸í·ÉµéÀ» ¼öÇàÇÏ°Ô ÇØ ÁÖÁö´Â ¾ÊÁö¸¸ °ø°ÝÀÚ°¡ SYS, SYSTEM ȤÀº CTXSYS¿Í °°Àº µðÆúÆ® »ç¿ëÀÚÀÇ ·Î±×Àΰú ÆÐ½º¿öµå¸¦ ÀÌ¿ë, ±ÇÇÑÀ» ¿Ã·Á¼­ µ¥ÀÌÅͺ£À̽º¿¡ Á¢¼ÓÇϴµ¥ »ç¿ëµÇ´Â »ç¿ëÀÚ ID¿Í ÆÐ½º¿öµå º¯°æÀ» ½ÃµµÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. °ø°ÝÀÚµéÀº ÃÖÁ¾ÀûÀ¸·Î ¼­ºñ½º°¡ °ÅºÎµÇ°Ô ÇÒ ¼ö ÀÖ´Ù.

»çÀÌÆ®°¡ Ãë¾àÇÑ »óÅ·ΠÀÖ´ÂÁö¸¦ Ã¼Å©ÇØ º¸±â À§Çؼ­´Â ´ÙÀ½°ú °°ÀÌ Å×½ºÆ®ÇØ º¼ ¼ö ÀÖ´Ù:
http://oracleserver/pls/portal30/admin_/

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/2150
http://www.iss.net/security_center/static/5818.php
ÇØ°áÃ¥ 1. $ORACLE_HOME$\Apache\modplsql\cfg µð·ºÅ丮¿¡ À§Ä¡ÇÑ DAD ¼³Á¤ ÆÄÀÏ "wdbsvr.app" ¸¦ ÆíÁýÇÑ´Ù.
2. ÆÄÀÏ¿¡¼­ "adminPath" ¿£Æ®¸®¸¦ µðÆúÆ® °æ·Î°¡ ¾Æ´Ñ »çÀûÀÎ(private) °æ·Î¸íÀ¸·Î ¼³Á¤ÇÑ´Ù (µðÆúÆ®: /admin_/).
3. ´ÙÀ½°ú °°ÀÌ "administrators" ¿£Æ®¸®¸¦ ¼³Á¤ÇÏ¿© °ü¸®ÀÚ ÆäÀÌÁö¿¡ Á¢±Ù ±ÇÇÑÀ» °®´Â »ç¿ëÀÚ¸¦ ÁöÁ¤ÇÑ´Ù (µðÆúÆ®: all) :
administrators = user1,user2
4. À¥ ¼­¹ö¸¦ Àç½ÃÀÛÇÑ´Ù.
°ü·Ã URL CVE-2000-1235 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)