| Ãë¾àÁ¡ID |
22129 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
ÇØ´ç Sambar À¥¼¹ö´Â ÆÐ½º¿öµå ¾øÀÌ °ü¸®ÀÚ ÆäÀÌÁö Á¢±ÙÀ» Çã¿ëÇÑ´Ù. Sambar ¼¹ö´Â À©µµ¿ìÁî ȯ°æ¿¡¼ »ç¿ëÇϵµ·Ï Á¦ÀÛµÈ ¸ÖƼ¾²·¹µå ¹æ½ÄÀÇ HTTP, FTP, Proxy ¼¹ö·Î, ȯ°æ ¼³Á¤À» À§ÇÑ À¥ ÀÎÅÍÆäÀ̽º¸¦ Á¦°øÇÑ´Ù. µðÆúÆ®·Î Sambar Server 4.1beta ¼¹ö´Â "admin" µðÆúÆ® °èÁ¤¿¡ ´ëÇØ ÆÐ½º¿öµå ¾øÀÌ ¹èÆ÷µÇ¾î Á³´Ù. ¶ÇÇÑ, ºñƯ±Ç °èÁ¤µéÀÌÁö¸¸ "anonymous", "guest" ¿Í °°Àº ÆÐ½º¿öµå°¡ ¼³Á¤µÇÁö ¾ÊÀº ´Ù¸¥ µðÆúÆ® °èÁ¤µéµµ Á¸ÀçÇÑ´Ù. µðÆúÆ® ¼³Á¤ÀÌ ±×´ë·Î ¹æÄ¡µÇ´Â °æ¿ì, ¿ø°ÝÁö °ø°ÝÀÚ´Â À¥ ¼¹ö¿¡ ºÒ¹ýÀûÀÎ Á¢±ÙÀÌ °¡´ÉÇϸç À̸¦ ÅëÇØ À¥ ¼¹ö¸¦ ÇØÅ·ÇÒ ¼ö ÀÖ´Ù. ¿¹¸¦ µé¾î, HTTP ·çÆ®¸¦ C:\ µå¶óÀ̺ê·Î ¼³Á¤À» ¹Ù²Ù¾î ³õ°í ±× ¾ÈÀÇ ÆÄÀϵéÀ» ÀÓÀÇ·Î »èÁ¦ÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/2255 http://www.iss.net/security_center/static/1669.php |
| ÇØ°áÃ¥ |
¿ø°ÝÁö °ø°ÝÀÚ°¡ ¼³Á¤À» º¯°æÇϱâ Àü¿¡ À¥ ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ "admin" ÀÇ »ç¿ëÀÚ¸í, ÆÐ½º¿öµå¸¦ º¸´Ù ¾ÈÀüÇÑ °ÍÀ¸·Î º¯°æÇÏ¿©¾ß ÇÑ´Ù.
º¯°æ ¹æ¹ý : 1. °ü¸®Àڷμ ·Î±×ÀÎÇϱâ À§ÇØ "http://hostname/session/adminlogin?RCpage=/sysadmin/index.stm" URLÀ» ÅëÇØ À¥ ÀÎÅÍÆäÀ̽º¿¡ Á¢¼ÓÇÑ´Ù. 2. "³×Æ®¿öÅ© ¾ÏÈ£ ÀÔ·Â" À©µµ¿ì âÀÌ ¶ß¸é ÆÐ½º¿öµå ¾øÀÌ »ç¿ëÀÚ¸í "admin"À» ÀÔ·ÂÇÏ¿© ·Î±×ÀÎÇÑ´Ù. 3. Sambar Information -> User Management -> root °æ·Î·ÎºÎÅÍ "admin" °èÁ¤À» ã´Â´Ù. 4. "Update User" ÇÁ·¹ÀÓ¿¡¼ "Password" ±âÀç¶õ¿¡ »õ·Î¿î ¾ÏÈ£¸¦ ÀÔ·ÂÇÑ´Ù. 5. <Update User> ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
-- OR --
Sambar À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© º£Å¸¹öÀüÀÌ ¾Æ´Ñ °¡Àå ÃֽйöÀü(5.2 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵åÇØ¾ß ÇÑ´Ù: http://www.brothersoft.com/sambar-server-5621.html |
| °ü·Ã URL |
CVE-1999-0508 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|