Ãë¾àÁ¡ID |
22152 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WWW |
»ó¼¼¼³¸í |
ÇØ´ç À¥ ¼¹ö´Â TRACE ¿Í(ȤÀº) TRACK MethodµéÀ» Áö¿øÇÑ´Ù. ÀÌ Method¸¦ Áö¿øÇÏ´Â ¼¹öµéÀº ´ëºÎºÐCross-Site-Scripting °ø°Ýµé¿¡ Ãë¾àÇѵ¥, ÀÌ´Â 'Cross-Site-Tracing' ȤÀº XST ¶ó´Â Ưº°ÇÑ À̸§À¸·Î ºÒ·ÁÁø´Ù. ÀÌ Ãë¾àÁ¡Àº °¢Á¾ ºê¶ó¿ìÁîµé¿¡ ÀÖ´Â ´Ù¾çÇÑ Ãë¾àÁ¡µé°ú °áÇÕÇÏ¿© »ç¿ëµÉ ¼ö ÀÖ´Ù. À¥ ¾îÇø®ÄÉÀÌ¼Ç º¸¾ÈÀ» Àü¹®À¸·Î ÇÏ°íÀÖ´Â WhiteHat Security »ç´Â Àü¼¼°è ¸ðµç À¥¼¹ö°¡ ¿µÇâÀ» ¹Þ´Â ½É°¢ÇÑ °áÇÔÀ» ¹ß°ßÇß´Ù. ¼ö°³¿ù¿¡ °ÉÄ£ ¿¬±¸¿Í Å×½ºÆ®¸¦ ÅëÇØ WhiteHat »ç´Â ¸ðµç À¥¼¹öµéÀÌ Åë½ÅÇÏ´Â ¹æ¹ý¿¡ °áÇÔÀ» µµ¿ëÇÏ´Â ¹æ¹ýÀ» ã¾Æ³Â´Ù. ÀÌ Ãë¾àÁ¡Àº À¥ ¼¹ö Á¢¼ÓÀ» µð¹ö±ë(ºÐ¼®) Çϴµ¥ »ç¿ëµÇ´Â TRACE Method¿¡ °áÇÔÀ» µµ¿ëÇÑ´Ù. ÀÌ´Â ¸ðµç ÁÖ¿ä À¥¼¹öµé¿¡ µðÆúÆ®·Î ÀÛµ¿µÇ´Â HTTP ÇÁ·ÎÅäÄÝÀÇ ÇÑ ºÎºÐÀ¸·Î °ÅÀÇ »ç¿ëµÇÁö´Â ¾Ê´Â´Ù. TRACE´Â HTTP ÇÁ·ÎÅäÄÝ ¸í¼¼¼ÀÇ ºÎºÐÀÌ¾î¼ Á¦°ÅÇϱⰡ ¾î·Æ´Ù. ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÀÚ´Â ¾î¶² À¥»çÀÌÆ®¸¦ °³¼³ÇÏ¿© ÀÌ ÆäÀÌÁö¸¦ ¹æ¹®ÇÏ´Â ¸ðµç »ç¿ëÀڷκÎÅÍ ÀüÀÚ»ó°Å·¡ »çÀÌÆ®, ¿Â¶óÀÎ ÀºÇà, À¥±â¹ÝÀÇ Email ½Ã½ºÅ۵鿡 Á¢¼ÓÇÒ ¼ö ÀÖ´Â »ç¿ëÀÚ Æнº¿öµå µîÀ» »©³¾ ¼ö ÀÖ´Ù. ÀÌ·¯ÇÑ ¾ÇÀÇÀûÀÎ À¥ÆäÀÌÁö´Â ¼ö¸¹Àº »ç¶÷µéÀ» ÇѲ¨¹ø¿¡ °ø°ÝÇϱâ À§ÇØ »ç¶÷µé¿¡°Ô Email·Î ¹è´ÞÇÒ ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.kb.cert.org/vuls/id/867593 http://archives.neohapsis.com/archives/bugtraq/2003-01/0230.html http://www.ietf.org/rfc/rfc2616.txt http://www.cgisecurity.com/whitehat-mirror/WH-WhitePaper_XST_ebook.pdf http://www.cgisecurity.com/whitehat-mirror/WhitePaper_screen.pdf
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: ¸ðµç HTTP ¼¹ö ¸ðµç ¹öÀü ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
À¥¼¹ö·ÎºÎÅÍ TRACE ¿Í(ȤÀº) TRACK MethodµéÀ» Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.
Microsoft IISÀÇ °æ¿ì: URLScanÀ» ÀÌ¿ëÇϸé ÀÌ MethodµéÀº µðÆúÆ®·Î ÇÊÅ͸µµÈ´Ù. URLScanÀº http://www.microsoft.com/en-us/download/details.aspx?id=12719 ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Ù. UrlscanÀº IIS Lockdown Åø ( http://www.microsoft.com/en-us/download/details.aspx?id=25064 )°ú ÇÔ²² ¾²ÀÏ ¼ö ÀÖ´Â °·ÂÇÑ º¸¾È Åø·Î, IIS À¥ »çÀÌÆ® °ü¸®ÀÚµéÀÌ ºÒÇÊ¿äÇÑ ±â´ÉµéÀ» Á¦°ÅÇÏ°í ¼¹ö°¡ ó¸®ÇØ¾ß ÇÒ HTTP ¿äûµéÀÇ Á¾·ù¸¦ Á¦ÇÑÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. Ưº°ÇÑ HTTP ¿äûµéÀ» Â÷´ÜÇÔÀ¸·Î½á, Urlscan º¸¾È ÅøÀº ÀáÀçÀûÀ¸·Î ÇØ·Î¿î ¿äûµéÀÌ ¼¹ö¿¡ µµ´ÞÇϰųª ¼Õ»óÀ» ÀÔÈ÷·Á´Â °ÍÀ¸·ÎºÎÅÍ Â÷´ÜÇÏ´Â ¿ªÇÒÀ» ÇØ ÁØ´Ù.
Apache 1.3 ¹èÆ÷ÆÇÀÇ °æ¿ì: Apache ¸ðµâÀÎ mod_rewriteÀÇ ±â´ÉÀ» »ç¿ëÇÔÀ¸·Î½á TRACE Method¸¦ Disable ½Ãų ¼ö ÀÖ´Ù. ÀÌ ¸ðµâÀº ·ê(Rule) ±â¹ÝÀ¸·Î ÀçÀÛ¼º ¿£ÁøÀ» Á¦°øÇÏ¿© ¿äûÇÑ URLµéÀ» Áï½Ã ÀçÀÛ¼ºÇØ ÁØ´Ù. µ¿Àû °øÀ¯ ¿ÀºêÁ§Æ®(DSO)·Î ¸¸µé¾îÁø ¸ðµâÀÇ ±â´ÉÀ» »ç¿ëÇϱâ À§Çؼ´Â httpd.conf ÆÄÀÏ¿¡¼ ÇÊ¿äÇÑ 'LoadModule' ¶óÀεéÀ» À§Ä¡½ÃÄÑ¾ß ÇÑ´Ù.
1. [Apache Ȩ µð·ºÅ丮]/conf/httpd.conf ÆÄÀÏÀ» ¿¬´Ù. 2. "LoadModule rewrite_module" Å×½ºÆ®¸¦ Æ÷ÇÔÇÏ´Â ¶óÀÎÀ» ã´Â´Ù. ¸¸¾à ±× ¶óÀÎÀÇ ½ÃÀÛ¿¡¼ #ÀÌ Á¸ÀçÇÑ´Ù¸é Á¦°ÅÇÑ´Ù. 3. ¶óÀγ»¿¡ ÀÖ´Â [module directory]°ú [module name]ÀÌ ¿Ã¹Ù¸¥Áö¸¦ È®ÀÎÇÑ´Ù. [module directory]Àº [Apache Ȩ µð·ºÅ丮] ¾Æ·¡¿¡ À§Ä¡ÇÏ¸ç ±× À̸§Àº ´ë°³ 'modules' ȤÀº 'libexec'·Î »ç¿ëµÈ´Ù. [module name]Àº ´ë°³ 'mod_rewrite.so', 'rewrite', ȤÀº À©µµ¿ì Ç÷§Æû¿¡¼´Â 'ApacheModuleRewrite.dll'À¸·Î ¸í¸íµÈ´Ù. LoadModule rewrite_module [module directory]/[module name] 4. ¸¸¾à "AddModule rewrite_module.c" ¶óÀÎÀÌ ÇÊ¿äÇÏ´Ù¸é "AddModule rewrite_module.c" ÅؽºÆ®¸¦ Æ÷ÇÔÇÏ´Â ¶óÀÎÀ» ã¾Æ ¶óÀÎÀÇ ½ÃÀÛ¿¡¼ #ÀÌ ÀÖÀ¸¸é »èÁ¦ÇÑ´Ù. 5. À§¿¡¼ ¼³Á¤ÇÑ ¶óÀÎµé ¾Æ·¡ ºÎºÐ¿¡ ´ÙÀ½ ¼¼ ¶óÀÎÀ» Ãß°¡ÇÑ´Ù: RewriteEngine on RewriteCond %{REQUEST_METHOD} ^TRACE RewriteRule .* - [F] 6. httpd ´ë¸óÀ» Àç½ÃÀÛÇÑ´Ù: [Apache Ȩ µð·ºÅ丮]/bin/apachctl restart
*±× ¿ÜÀÇ ApacheÀÇ °æ¿ì httpd.conf ÆÄÀÏÀ» ¿¬ ÈÄ ´ÙÀ½ÀÇ ¼³Á¤À» Ãß°¡ÇÏ¿© Àç½ÃÀÛÇÑ´Ù. TraceEnable Off
HP-UXÀÇ °æ¿ì: ´ÙÀ½ Hewlett-Packard Company Security Bulletin HPSBUX0309-279¸¦ ÂüÁ¶ÇÏ¿© HP-UX security bulletins digest¸¦ µû¸¥´Ù: http://archives.neohapsis.com/archives/hp/2003-q3/0053.html
Sun ONE/iPlanet Web ServerÀÇ °æ¿ì: ´ÙÀ½ Sun Alert Notification 50603À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù: http://download.oracle.com/sunalerts/1000125.1.html
Sun Java System Application ServerÀÇ °æ¿ì: ´ÙÀ½ Sun Alert Notification 57670À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù: http://download.oracle.com/sunalerts/1000718.1.html
±âŸ: ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
9561,11604 (SecurityFocus) |
°ü·Ã URL |
11237,11149 (ISS) |
|