English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22073
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Servlet
»ó¼¼¼³¸í Allaire JRun 3.0/3.1°ú Á¢¼ÓµÈ IIS 4.0/5.0À» ¿î¿µÁßÀÎ À©µµ¿ìÁî Ç÷§ÆûÀº '%3f.jsp'À¸·Î µÈ URLµéÀ» ´Ù·ç´Â µ¥¿¡ ¹®Á¦°¡ ÀÖ¾î, °ø°ÝÀÚ°¡ À¥¼­¹ö root µð·ºÅ丮 (´ë°³´Â \inetpub\wwwroot) ¾Æ·¡¿¡ ÀÖ´Â ÆÄÀϽýºÅÛÀ» ¾×¼¼½ºÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
¿¹¸¦µé¾î:

http://www.target.com/%3f.jsp

ÀÌ ¹®Á¦Á¡Àº ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® IIS¿¡¼­¸¸ ÇØ´çµÈ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/windowsntfocus/6N0140035G.html
http://www.iss.net/security_center/static/7623.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
IIS 4.0/5.0
ÇØ°áÃ¥ Macromedia»ç´Â °¡Àå ÁÁÀº ¹æ¹ýÀ¸·Î ´ÙÀ½ ¾ÖÇø®ÄÉÀ̼ǵ鿡 ÀÖ´Â JRun Default Server¿¡ ´ëÇÑ µð·ºÅ丮 ºê¶ó¿ì¡À» Off ½ÃÄѳõÀ» °ÍÀ» ±Ç°íÇÑ´Ù.

- Default Application (the application with '/' mapping that causes the security problem)
- Demo Application

¶ÇÇÑ '/' ¸ÊÇÎÀ» »ç¿ëÇÏ´Â »õ·Ó°Ô »ý¼ºµÇ´Â À¥ ¾ÖÇø®ÄÉÀ̼ǵ鵵 ¹Ýµå½Ã µð·ºÅ丮 ºê¶ó¿ì¡ÀÌ Off µÇµµ·Ï ÇØ¾ß ÇÑ´Ù.

JMC(JRun Management Console)¿¡¼­ÀÇ º¯°æ:
- JRun Default Server/Web Applications/Default User Application/File Settings/Directory Browsing Allowed ¸¦ FALSE·Î ¼³Á¤
- JRun Default Server/Web Applications/JRun Demo/File Settings/ Directory Browsing Allowed ¸¦ FALSE·Î ¼³Á¤

º¯°æÀÛ¾÷ ÈÄ¿¡´Â ¼­¹ö¸¦ Àç½ÃÀÛÇØ¾ßÇÑ´Ù. ±×¸®°í '%3f.jsp' ¿äû¿¡ ´ëÇØ 403 forbiddenÀÌ ¸®Åϵǵµ·Ï ÇØ¾ß ÇÑ´Ù. ÀÌ ¹ö±×°¡ Fix µÉ ¶§ (µð·ºÅ丮 ºê¶ó¿ì¡ ¼³Á¤°ú °ü°è¾øÀÌ) ±× ¿äûÀº '404 page not found'¸¦ ¸®ÅÏÇØ¾ß ÇÑ´Ù.

µð·ºÅ丮 ºÎ¶ó¿ì¡ Property´Â [file.browsedirs]·Î ºÒ·ÁÁø´Ù. JMC¸¦ ÅëÇÑ ±× propertyÀÇ º¯°æÀº ´ÙÀ½°ú °°ÀÌ ÇÒ ¼ö ÀÖ´Ù:
JRun 3.0Àº (server-wide º¯°æ) local.properties ÆÄÀÏ¿¡¼­ [file.browsedirs=false]À» ±â·Ï
JRun 3.1Àº ¾ÖÇø®ÄÉÀ̼ÇÀÇ webapp.properties¿¡¼­ [file.browsedirs=false]À» ±â·Ï
°ü·Ã URL CVE-2001-1510 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)