English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22119
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÆÄÀÏ¸í ¾Õ¿¡ ¼ö°³ÀÇ '.'(dot) µéÀ» µ¡ºÙÀÓÀ¸·Î½á À¥¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» Àо ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº MS Personal Web Server (PWS)¿Í FrontPage PWSÀÇ ±¸¹öÀü¿¡ Á¸ÀçÇÑ´Ù. Attacker°¡ ÀÌ·¯ÇÑ Ãë¾àÁ¡À» ÀÌ¿ëÇØ¼­ ÆÄÀÏÀ» Àоî¿À±â À§Çؼ­´Â »çÀü¿¡ ½Ã½ºÅÛ ³»ÀÇ ÆÄÀϸíÀ» ¾Ë°í ÀÖ¾î¾ß Çϸç Àб⠱ÇÇÑÀÌ Çã¿ëµÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.

¿¹¸¦µé¾î ´ÙÀ½°ú °°ÀÌ Çϸé ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇØ ÆÄÀÏÀ» Àоî¿Ã ¼ö ÀÖ´Ù.
GET ........../config.sys

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/2036.php
http://www.microsoft.com/technet/security/bulletin/ms99-010.asp
ÇØ°áÃ¥ MSÀÇ Patch Site·Î ºÎÅÍ Pwssecup.exe patch¸¦ ±¸Çؿͼ­ ¼³Ä¡ÇØ¾ß ÇÑ´Ù.
http://technet.microsoft.com/en-us/security/bulletin/ms99-010
°ü·Ã URL CVE-1999-0386,CVE-2000-0153 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)