| Ãë¾àÁ¡ID |
22065 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
Microsoft Index Server¿¡ Ãë¾àÁ¡ÀÌ ÀÖ¾î À¥¼¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀÇ ³»¿ëÀ» º¼ ¼ö ÀÖ´Ù. Microsoft Index Server´Â Windows NT 4.0 Option Pack¿¡ Æ÷ÇÔµÈ À¥ °Ë»ö¿£ÁøÀÌ´Ù. ÀÌ Áß idq.dll ÆÄÀÏ¿¡ ¹®Á¦°¡ ÀÖ¾î Á¶ÀÛµÈ URL¸¦ ¿äûÇÔÀ¸·Î½á °¡»ó µð·ºÅ丮 ¿ÜÀÇ µð·ºÅ丮µé¿¡ ´ëÇÑ °Ë»öÀ» Çã¿ëÇÑ´Ù. À̷νá Attacker´Â À¥¼¹ö°¡ ¼³Ä¡µÈ µå¶óÀÌºê »óÀÇ ¾î¶² ÆÄÀÏÀ̵ç Àоî¿Ã ¼ö ÀÖ´Ù. ´ÙÀ½°ú °°ÀÌ Request¸¦ ÇÏ°Ô µÇ¸é win.ini ÆÄÀÏÀ» Àоî¿Ã ¼ö ÀÖ´Ù.
GET http://target/query.idq?CiTemplate=../../../../../winnt/win.ini
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/4232.php http://www.microsoft.com/technet/security/bulletin/ms00-006.asp |
| ÇØ°áÃ¥ |
Microsoft Security Bulletin MS00-006¿¡¼ Patch¸¦ ±¸ÇÒ ¼ö ÀÖ´Ù. º¸ÃæÇÏÀÚ¸é IDQ ÆÄÀϵéÀº .HTX ÆÄÀϵéÀÌ Ãâ·Â Çü½ÄÀ» ¸¸µé ¶§¿¡¸¸ »ç¿ëÀÚ ÀÔ·ÂÀ» Á¦ÇÑÇÏ´Â °ÍÀ» ¾Ë¾Æ¾ß ÇÑ´Ù. ¸î¸î ¿¹Á¦ ÆÄÀϵéÀº »ç¿ëÀÚ ÀԷ¿¡ ´ëÇØ ÃæºÐÈ÷ Á¦ÇÑÇÏÁö ¾ÊÀº °æ¿ì°¡ ¸¹±â ¶§¹®¿¡ ¿¹Á¦ ÆÄÀϵéÀº production ¼¹ö¿¡¼ ¹Ýµå½Ã Á¦°ÅÇÒ Çʿ䰡 ÀÖ´Ù. |
| °ü·Ã URL |
CVE-2000-0126 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|