| Ãë¾àÁ¡ID |
22066 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
Microsoft Index Server¿¡ Ãë¾àÁ¡ÀÌ ÀÖ¾î À¥¼¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀÇ ³»¿ëÀ» º¼ ¼ö ÀÖ´Ù. Microsoft Index Server´Â Windows NT 4.0 Option Pack¿¡ Æ÷ÇÔµÈ À¥ °Ë»ö¿£ÁøÀÌ´Ù. ÀÌ Áß idq.dll ÆÄÀÏ¿¡ ¹®Á¦°¡ ÀÖ¾î Á¶ÀÛµÈ URL¸¦ ¿äûÇÔÀ¸·Î½á °¡»ó µð·ºÅ丮 ¿ÜÀÇ µð·ºÅ丮µé¿¡ ´ëÇÑ °Ë»öÀ» Çã¿ëÇÑ´Ù. À̷νá Attacker´Â À¥¼¹ö°¡ ¼³Ä¡µÈ µå¶óÀÌºê »óÀÇ ¾î¶² ÆÄÀÏÀ̵ç Àоî¿Ã ¼ö ÀÖ´Ù. ´ÙÀ½°ú °°ÀÌ Request¸¦ ÇÏ°Ô µÇ¸é win.ini ÆÄÀÏÀ» Àоî¿Ã ¼ö ÀÖ´Ù.
GET http://target/query.idq?CiTemplate=../../../../../winnt/win.ini
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/3884.php http://www.microsoft.com/technet/security/bulletin/ms00-006.asp |
| ÇØ°áÃ¥ |
WebHits¿¡ ÀÇÇØ Á¦°øµÇ´Â ±â´ÉÀÌ ÇÊ¿äÇÏ´Ù¸é ´ÙÀ½ »çÀÌÆ®¿¡¼ Patch¸¦ ¹Þ¾Æ ¼³Ä¡ÇØ¾ß ÇÑ´Ù.
http://www.microsoft.com/technet/security/bulletin/ms00-006.asp
ÀÌ ±â´ÉÀÌ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é Internet Service Manager MMC snap-inÀ» »ç¿ëÇÏ¿© webhits.dll·Î ºÎÅÍ .htw extensions¸¦ unmapÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2000-0097 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|