English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22061
À§Çèµµ 30
Æ÷Æ® 80
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö´Â À§ÇèÇÑ HTTP methodÀÎ DELETEÀÇ ½ÇÇàÀ» Çã¿ëÇÑ´Ù.

À߸ø ±¸ÃàµÈ À¥¼­¹öµéÀº PUTÀ̳ª DELETE¿Í °°Àº À§ÇèÇÑ ¸î¸î HTTP methodµéÀÌ ½ÇÇàµÉ ¼ö ÀÖµµ·Ï Çã¿ëÇÑ´Ù. ÀÌ Áß 'DELETE' Method´Â Ŭ¶óÀÌ¾ðÆ®°¡ À¥¼­¹ö »óÀÇ ÀÓÀÇÀÇ ¿ÀºêÁ§Æ®¸¦ »èÁ¦ÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â 'DELETE' Method¸¦ ÀÌ¿ëÇÏ¿© À¥¼­¹ö »ó¿¡ ÀÖ´Â ÀϺΠÀ¥ ÆäÀÌÁöµéÀ» Áö¿ö ¹ö¸± ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/4253.php
ÇØ°áÃ¥ ÀûÀýÇÑ ¼­¹ö ¼³Á¤À» ÅëÇØ¼­ PUTÀ̳ª DELETE¿Í °°Àº À§ÇèÇÑ HTTP method µéÀÇ ½ÇÇàÀ» Á¦ÇÑÇØ¾ß ÇÑ´Ù. ¹Ýµå½Ã ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ÀÌ·¯ÇÑ methodµéÀÇ »ç¿ëÀ» ±ÝÁöÇØ¾ß ÇÑ´Ù.

¿¹¸¦µé¾î ApacheÀÇ °æ¿ì ÇØ´ç µð·ºÅ͸®¿¡¼­ ´ÙÀ½°ú °°ÀÌ ¼³Á¤ÇÑ´Ù.
<Directory /abcd>
<Limit PUT DELETE OPTIONS> //Â÷´ÜÇÒ method
Order deny, allow
alow from IP // Çã¿ëÇÒ IP
</Limit>
</Directory>
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)