English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22123
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç Apache À¥¼­¹ö´Â µð·ºÅ丮 Ž»ö Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Apache´Â °­·ÂÇÏ°í ¸ðµç ±â´ÉÀ» µÎ·ç °®Ãá È¿°úÀûÀÌ¸ç ¹«·á·Î ÀÚÀ¯·Ó°Ô »ç¿ëÇÒ ¼ö ÀÖ´Â À¥¼­¹öÀÌ´Ù. À©µµ¿ìÁî ½Ã½ºÅÛ¿ëÀÇ Apache ¹öÀü 2.0.39 ÀÌÇÏÀÇ ¹öÀüµéÀº °ø°ÝÀÚ°¡ ¿ø°ÝÀ¸·Î À¥ Root ¹ÛÀÇ ÀÓÀÇÀÇ ÆÄÀϵéÀ» º¼ ¼ö ÀÖ°Ô ÇØÁÖ¸ç À¥¼­¹ö Root¿Í °°Àº ÆÄƼ¼Ç »óÀÇ ÀÓÀÇÀÇ ¸í·ÉµéÀÇ ½ÇÇà±îÁö Çã¿ëÇÑ´Ù.
¹®Á¦´Â »ç¿ëÀÚ¿¡ ÀÇÇØ º¸³»Áø ¾ÇÀÇÀûÀÎ ¹®ÀÚµéÀÇ ÇÊÅ͸µ °úÁ¤¿¡ ÀÖ´Ù. ÀÌ °æ¿ì¿¡ À־´Â ¹é½½·¡½¬ ¹®ÀÚ ('\' == %5c)°¡ ÇÊÅ͵ÇÁö ¾Ê¾Æ °ø°ÝÀÚ¿¡°Ô Á¤»óÀûÀ¸·Î Á¦¾àµÇ¾îÁ®¾ß ÇÏ´Â HTTP root µð·ºÅ丮 ¿ÜºÎÀÇ µð·ºÅ丮µéÀ» Á¢±ÙÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ÀÌ Ãë¾àÁ¡Àº ½ÉÁö¾î /cgi-bin µð·ºÅ丮·Î ½ÃÀ۵Ǵ ¿äûÀ» º¸³¿À¸·Î½á °ø°ÝÀÚ´Â ÀÚ½ÅÀÌ ¿äûÇÑ ÆÄÀÏÀ» ½ÇÇàÇÒ ¼öµµ ÀÖ´Ù.

¿¹)
´ÙÀ½°ú °°ÀÌÇϸé winnt\win.in ÆÄÀÏÀ» º¼ ¼ö ÀÖ´Ù:
http://127.0.0.1/error/%5c%2e%2e%5c%2e%2e%5c%2e%2e%5c%2e%2e%5cwinnt%5cwin.ini

´ÙÀ½°ú °°ÀÌÇϸé Apache2/bin Æú´õ¿¡ ÀÖ´Â "wintty" À¯Æ¿¸®Æ¼¸¦ ½ÇÇà½Ãų ¼ö ÀÖ´Ù:
http://127.0.0.1/cgi-bin/%5c%2e%2e%5cbin%5cwintty.exe?%2dt+HELLO

Ãë¾àÇÑ Ç÷§Æû:
* Apache À¥¼­¹ö ¹öÀü 2.0.39°ú ÀÌÀüÀÇ 2.0.x ¹öÀüµé (Windows/Netware/OS2)

* Âü°í »çÀÌÆ®:
http://httpd.apache.org/info/security_bulletin_20020908a.txt
http://www.securiteam.com/windowsntfocus/5ZP0C2A80Y.html
ÇØ°áÃ¥ Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â httpd.conf ÆÄÀϳ»ÀÇ Ã¹¹øÂ° 'Alias' ³ª 'Redirect' Áö½ÃÀÚ ¾Õ¿¡ Global ¼­¹ö ¼³Á¤À¸·Î ´ÙÀ½ Áö½ÃÀÚ¸¦ Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù:

RedirectMatch 400 "\\\.\."

-- ȤÀº --

Apache À¥»çÀÌÆ® http://httpd.apache.org ·ÎºÎÅÍ Apache 2.0.40 ÀÌ»óÀÇ ¹öÀüÀ» ±¸ÇÏ¿© ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2002-0661 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)