English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22065
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í Microsoft Index Server¿¡ Ãë¾àÁ¡ÀÌ ÀÖ¾î À¥¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀÇ ³»¿ëÀ» º¼ ¼ö ÀÖ´Ù. Microsoft Index Server´Â Windows NT 4.0 Option Pack¿¡ Æ÷ÇÔµÈ À¥ °Ë»ö¿£ÁøÀÌ´Ù. ÀÌ Áß idq.dll ÆÄÀÏ¿¡ ¹®Á¦°¡ ÀÖ¾î Á¶ÀÛµÈ URL¸¦ ¿äûÇÔÀ¸·Î½á °¡»ó µð·ºÅ丮 ¿ÜÀÇ µð·ºÅ丮µé¿¡ ´ëÇÑ °Ë»öÀ» Çã¿ëÇÑ´Ù. À̷νá Attacker´Â À¥¼­¹ö°¡ ¼³Ä¡µÈ µå¶óÀÌºê »óÀÇ ¾î¶² ÆÄÀÏÀ̵ç Àоî¿Ã ¼ö ÀÖ´Ù.
´ÙÀ½°ú °°ÀÌ Request¸¦ ÇÏ°Ô µÇ¸é win.ini ÆÄÀÏÀ» Àоî¿Ã ¼ö ÀÖ´Ù.

GET http://target/query.idq?CiTemplate=../../../../../winnt/win.ini

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/4232.php
http://www.microsoft.com/technet/security/bulletin/ms00-006.asp
ÇØ°áÃ¥ Microsoft Security Bulletin MS00-006¿¡¼­ Patch¸¦ ±¸ÇÒ ¼ö ÀÖ´Ù. º¸ÃæÇÏÀÚ¸é IDQ ÆÄÀϵéÀº .HTX ÆÄÀϵéÀÌ Ãâ·Â Çü½ÄÀ» ¸¸µé ¶§¿¡¸¸ »ç¿ëÀÚ ÀÔ·ÂÀ» Á¦ÇÑÇÏ´Â °ÍÀ» ¾Ë¾Æ¾ß ÇÑ´Ù. ¸î¸î ¿¹Á¦ ÆÄÀϵéÀº »ç¿ëÀÚ ÀԷ¿¡ ´ëÇØ ÃæºÐÈ÷ Á¦ÇÑÇÏÁö ¾ÊÀº °æ¿ì°¡ ¸¹±â ¶§¹®¿¡ ¿¹Á¦ ÆÄÀϵéÀº production ¼­¹ö¿¡¼­ ¹Ýµå½Ã Á¦°ÅÇÒ Çʿ䰡 ÀÖ´Ù.
°ü·Ã URL CVE-2000-0126 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)