English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22050
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Oracle 9iAS¿¡ ÀÖ´Â JSP ¼Ò½º ÆÄÀÏÀÌ ¾×¼¼½º µÇ¾îÁø´Ù. Oracle 9iAS°¡ °¡Áø À¥ ¼­ºñ½º´Â Apache¿Í Àß °áÇÕÇÏ¿© SOAP, PL/SQL, XSQL, ±×¸®°í JSP¸¦ Æ÷ÇÔÇÑ ¸¹Àº ¾ÖÇø®ÄÉÀÌ¼Ç È¯°æµéÀ» Á¦°øÇÑ´Ù.
Oracle 9iASÀÇ µðÆúÆ® ¼³Ä¡¿¡ º¸¾È ¹®Á¦°¡ Á¸ÀçÇÏ¿© °ø°ÝÀÚ°¡ ¹ø¿ªµÈ JSP ÆäÀÌÁöÀÇ ¼Ò½º Äڵ带 ¾×¼¼½º ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. JSP°¡ ¿äûµÇ¸é °ð¹Ù·Î ÄÄÆÄÀÏµÇ¾î °á°ú HTML ÆäÀÌÁö°¡ »ç¿ëÀÚ¿¡°Ô ¸®ÅϵȴÙ. Oracle 9iAS´Â ÄÄÆÄÀϽÿ¡ ¸Å°³ ÆÄÀϵéÀ» ´Ù·ç±â À§ÇØ ¾î¶² Æú´õ¸¦ »ç¿ëÇϴµ¥, ÀÌ ÆÄÀϵéÀº .JSP ÆäÀÌÁö°¡ »óÁÖÇÏ´Â µ¿ÀÏÇÑ Æú´õ¿¡ »ý¼ºµÈ´Ù. °á±¹, ÁÖ¾îÁø JSP ÆäÀÌÁö¸¦ À§ÇÑ .java¿Í ÄÄÆÄÀÏµÈ .class ÆÄÀϵéÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ°Ô µÈ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-2002-08.html
http://marc.info/?l=bugtraq&m=101301440005580&w=2
ÇØ°áÃ¥ $ORACLE_HOME$/apache/apache/conf¿¡ ÀÖ´Â httpd.conf ÆÄÀÏÀ» ÆíÁýÇÏ¿© ´ÙÀ½ ¿£Æ®¸®µéÀ» Ãß°¡ÇØ¾ß ÇÑ´Ù:

* globals.jsa ÆÄÀÏ·ÎÀÇ ¾×¼¼½º¸¦ ¸·±â À§Çؼ­´Â ´ÙÀ½ ¿£Æ®¸®¸¦ Ãß°¡ÇØ¾ß ÇÑ´Ù:
<Files ~ "^\globals.jsa">
Order allow,deny
Deny from all
</Files>

* .java ÆäÀÌÁöµé¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¸·±â À§Çؼ­´Â ´ÙÀ½ ¿£Æ®¸®¸¦ Ãß°¡ÇØ¾ß ÇÑ´Ù:
<Location /_pages>
Order deny,allow
Deny from all
</Location>

* ¸¸¾à JSP ÆäÀÌÁöµéÀÌ º°Äª µð·ºÅ丮 (Áï, "htdocs"ÀÇ ÇÏÀ§ µð·ºÅ丮°¡ ¾Æ´Ï¶ó)¿¡ ÀúÀåµÇ¾î ÀÖ´Ù¸é ´ÙÀ½ ¿£Æ®¸®¸¦ Ãß°¡ÇØ¾ß ÇÑ´Ù:

<Location /dirname/_pages>
Order deny,allow
Deny from all
</Location>

¿©±â¿¡¼­ "dirname"Àº º°Äª µð·ºÅ丮ÀÇ À̸§ÀÌ´Ù.
°ü·Ã URL CVE-2002-0562 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)