English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22152
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç À¥ ¼­¹ö´Â TRACE ¿Í(ȤÀº) TRACK MethodµéÀ» Áö¿øÇÑ´Ù. ÀÌ Method¸¦ Áö¿øÇÏ´Â ¼­¹öµéÀº ´ëºÎºÐCross-Site-Scripting °ø°Ýµé¿¡ Ãë¾àÇѵ¥, ÀÌ´Â 'Cross-Site-Tracing' ȤÀº XST ¶ó´Â Ưº°ÇÑ À̸§À¸·Î ºÒ·ÁÁø´Ù. ÀÌ Ãë¾àÁ¡Àº °¢Á¾ ºê¶ó¿ìÁîµé¿¡ ÀÖ´Â ´Ù¾çÇÑ Ãë¾àÁ¡µé°ú °áÇÕÇÏ¿© »ç¿ëµÉ ¼ö ÀÖ´Ù.
À¥ ¾îÇø®ÄÉÀÌ¼Ç º¸¾ÈÀ» Àü¹®À¸·Î ÇÏ°íÀÖ´Â WhiteHat Security »ç´Â Àü¼¼°è ¸ðµç À¥¼­¹ö°¡ ¿µÇâÀ» ¹Þ´Â ½É°¢ÇÑ °áÇÔÀ» ¹ß°ßÇß´Ù. ¼ö°³¿ù¿¡ °ÉÄ£ ¿¬±¸¿Í Å×½ºÆ®¸¦ ÅëÇØ WhiteHat »ç´Â ¸ðµç À¥¼­¹öµéÀÌ Åë½ÅÇÏ´Â ¹æ¹ý¿¡ °áÇÔÀ» µµ¿ëÇÏ´Â ¹æ¹ýÀ» ã¾Æ³Â´Ù.
ÀÌ Ãë¾àÁ¡Àº À¥ ¼­¹ö Á¢¼ÓÀ» µð¹ö±ë(ºÐ¼®) Çϴµ¥ »ç¿ëµÇ´Â TRACE Method¿¡ °áÇÔÀ» µµ¿ëÇÑ´Ù. ÀÌ´Â ¸ðµç ÁÖ¿ä À¥¼­¹öµé¿¡ µðÆúÆ®·Î ÀÛµ¿µÇ´Â HTTP ÇÁ·ÎÅäÄÝÀÇ ÇÑ ºÎºÐÀ¸·Î °ÅÀÇ »ç¿ëµÇÁö´Â ¾Ê´Â´Ù. TRACE´Â HTTP ÇÁ·ÎÅäÄÝ ¸í¼¼¼­ÀÇ ºÎºÐÀ̾ Á¦°ÅÇϱⰡ ¾î·Æ´Ù.
ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÀÚ´Â ¾î¶² À¥»çÀÌÆ®¸¦ °³¼³ÇÏ¿© ÀÌ ÆäÀÌÁö¸¦ ¹æ¹®ÇÏ´Â ¸ðµç »ç¿ëÀڷκÎÅÍ ÀüÀÚ»ó°Å·¡ »çÀÌÆ®, ¿Â¶óÀÎ ÀºÇà, À¥±â¹ÝÀÇ Email ½Ã½ºÅ۵鿡 Á¢¼ÓÇÒ ¼ö ÀÖ´Â »ç¿ëÀÚ Æнº¿öµå µîÀ» »©³¾ ¼ö ÀÖ´Ù. ÀÌ·¯ÇÑ ¾ÇÀÇÀûÀÎ À¥ÆäÀÌÁö´Â ¼ö¸¹Àº »ç¶÷µéÀ» ÇѲ¨¹ø¿¡ °ø°ÝÇϱâ À§ÇØ »ç¶÷µé¿¡°Ô Email·Î ¹è´ÞÇÒ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.kb.cert.org/vuls/id/867593
http://archives.neohapsis.com/archives/bugtraq/2003-01/0230.html
http://www.ietf.org/rfc/rfc2616.txt
http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf
http://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdf


* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
¸ðµç HTTP ¼­¹ö ¸ðµç ¹öÀü
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ À¥¼­¹ö·ÎºÎÅÍ TRACE ¿Í(ȤÀº) TRACK MethodµéÀ» Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.

Microsoft IISÀÇ °æ¿ì:
URLScanÀ» ÀÌ¿ëÇϸé ÀÌ MethodµéÀº µðÆúÆ®·Î ÇÊÅ͸µµÈ´Ù. URLScanÀº http://www.microsoft.com/en-us/download/details.aspx?id=12719 ¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù.
UrlscanÀº IIS Lockdown Åø ( http://www.microsoft.com/en-us/download/details.aspx?id=25064 )°ú ÇÔ²² ¾²ÀÏ ¼ö ÀÖ´Â °­·ÂÇÑ º¸¾È Åø·Î, IIS À¥ »çÀÌÆ® °ü¸®ÀÚµéÀÌ ºÒÇÊ¿äÇÑ ±â´ÉµéÀ» Á¦°ÅÇÏ°í ¼­¹ö°¡ ó¸®ÇØ¾ß ÇÒ HTTP ¿äûµéÀÇ Á¾·ù¸¦ Á¦ÇÑÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. Ưº°ÇÑ HTTP ¿äûµéÀ» Â÷´ÜÇÔÀ¸·Î½á, Urlscan º¸¾È ÅøÀº ÀáÀçÀûÀ¸·Î ÇØ·Î¿î ¿äûµéÀÌ ¼­¹ö¿¡ µµ´ÞÇϰųª ¼Õ»óÀ» ÀÔÈ÷·Á´Â °ÍÀ¸·ÎºÎÅÍ Â÷´ÜÇÏ´Â ¿ªÇÒÀ» ÇØ ÁØ´Ù.

Apache 1.3 ¹èÆ÷ÆÇÀÇ °æ¿ì:
Apache ¸ðµâÀÎ mod_rewriteÀÇ ±â´ÉÀ» »ç¿ëÇÔÀ¸·Î½á TRACE Method¸¦ Disable ½Ãų ¼ö ÀÖ´Ù. ÀÌ ¸ðµâÀº ·ê(Rule) ±â¹ÝÀ¸·Î ÀçÀÛ¼º ¿£ÁøÀ» Á¦°øÇÏ¿© ¿äûÇÑ URLµéÀ» Áï½Ã ÀçÀÛ¼ºÇØ ÁØ´Ù. µ¿Àû °øÀ¯ ¿ÀºêÁ§Æ®(DSO)·Î ¸¸µé¾îÁø ¸ðµâÀÇ ±â´ÉÀ» »ç¿ëÇϱâ À§Çؼ­´Â httpd.conf ÆÄÀÏ¿¡¼­ ÇÊ¿äÇÑ 'LoadModule' ¶óÀεéÀ» À§Ä¡½ÃÄÑ¾ß ÇÑ´Ù.

1. [Apache Ȩ µð·ºÅ丮]/conf/httpd.conf ÆÄÀÏÀ» ¿¬´Ù.
2. "LoadModule rewrite_module" Å×½ºÆ®¸¦ Æ÷ÇÔÇÏ´Â ¶óÀÎÀ» ã´Â´Ù. ¸¸¾à ±× ¶óÀÎÀÇ ½ÃÀÛ¿¡¼­ #ÀÌ Á¸ÀçÇÑ´Ù¸é Á¦°ÅÇÑ´Ù.
3. ¶óÀγ»¿¡ ÀÖ´Â [module directory]°ú [module name]ÀÌ ¿Ã¹Ù¸¥Áö¸¦ È®ÀÎÇÑ´Ù. [module directory]Àº [Apache Ȩ µð·ºÅ丮] ¾Æ·¡¿¡ À§Ä¡ÇÏ¸ç ±× À̸§Àº ´ë°³ 'modules' ȤÀº 'libexec'·Î »ç¿ëµÈ´Ù. [module name]Àº ´ë°³ 'mod_rewrite.so', 'rewrite', ȤÀº À©µµ¿ì Ç÷§Æû¿¡¼­´Â 'ApacheModuleRewrite.dll'À¸·Î ¸í¸íµÈ´Ù.
LoadModule rewrite_module [module directory]/[module name]
4. ¸¸¾à "AddModule rewrite_module.c" ¶óÀÎÀÌ ÇÊ¿äÇÏ´Ù¸é "AddModule rewrite_module.c" ÅؽºÆ®¸¦ Æ÷ÇÔÇÏ´Â ¶óÀÎÀ» ã¾Æ ¶óÀÎÀÇ ½ÃÀÛ¿¡¼­ #ÀÌ ÀÖÀ¸¸é »èÁ¦ÇÑ´Ù.
5. À§¿¡¼­ ¼³Á¤ÇÑ ¶óÀÎµé ¾Æ·¡ ºÎºÐ¿¡ ´ÙÀ½ ¼¼ ¶óÀÎÀ» Ãß°¡ÇÑ´Ù:
RewriteEngine on
RewriteCond %{REQUEST_METHOD} ^TRACE
RewriteRule .* - [F]
6. httpd ´ë¸óÀ» Àç½ÃÀÛÇÑ´Ù:
[Apache Ȩ µð·ºÅ丮]/bin/apachctl restart

*±× ¿ÜÀÇ ApacheÀÇ °æ¿ì httpd.conf ÆÄÀÏÀ» ¿¬ ÈÄ ´ÙÀ½ÀÇ ¼³Á¤À» Ãß°¡ÇÏ¿© Àç½ÃÀÛÇÑ´Ù.
TraceEnable Off

HP-UXÀÇ °æ¿ì:
´ÙÀ½ Hewlett-Packard Company Security Bulletin HPSBUX0309-279¸¦ ÂüÁ¶ÇÏ¿© HP-UX security bulletins digest¸¦ µû¸¥´Ù:
http://archives.neohapsis.com/archives/hp/2003-q3/0053.html

Sun ONE/iPlanet Web ServerÀÇ °æ¿ì:
´ÙÀ½ Sun Alert Notification 50603À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù:
http://download.oracle.com/sunalerts/1000125.1.html

Sun Java System Application ServerÀÇ °æ¿ì:
´ÙÀ½ Sun Alert Notification 57670À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù:
http://download.oracle.com/sunalerts/1000718.1.html

±âŸ:
ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 9561,11604 (SecurityFocus)
°ü·Ã URL 11237,11149 (ISS)