| Ãë¾àÁ¡ID |
22191 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
ÇØ´ç FrontPage Server Extensions¿¡´Â ±ÇÇÑÀÌ ºÎÀûÀýÇÏ°Ô ¼³Á¤µÇ¾î ÀÖ´Ù. FrontPage Sever Extensions´Â µðÆúÆ®·Î Internet Information Server(IIS) ¼¹ö¿Í ÇÔ²² ¼³Ä¡µÇ¸ç, À¥ °ü¸®ÀÚ³ª °³¹ßÀÚµéÀÌ FrontPage Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥(FrontPage 2000)À» ÅëÇØ¼ Á÷Á¢ À¥ ÆäÀÌÁö¸¦ ÀÛ¼ºÇÏ°í ¼¹ö¸¦ °ü¸®ÇÒ ¼ö ÀÖ´Â ±â´ÉÀ» Á¦°øÇÑ´Ù. FrontPage sever extensions ÀÌ ¼³Ä¡µÈ ¼¹ö¿¡´Â ¼¼ °¡Áö ÆÄÀÏ, Áï "shtml.dll", "_vti_adm\admin.dll", ±×¸®°í "_vti_aut\author.dll" ÆÄÀϵéÀÌ "_vti_bin" µð·ºÅ丮¿¡ »ý¼ºµÈ´Ù. "admin.dll", "author.dll" °ú °°Àº extension ÆÄÀÏÀº º¸¾ÈÀ» À§ÇØ Àΰ¡µÈ »ç¿ëÀÚµé(À¥ °ü¸®ÀÚ, °³¹ßÀÚ)¿¡°Ô¸¸ Á¢±Ù ±ÇÇÑÀÌ Çã¿ëµÇ¾î¾ß ÇÑ´Ù. ÇÏÁö¸¸, FrontPage Server Extensions »ó¿¡ Á¢±Ù ±ÇÇÑ ¼³Á¤ÀÌ ºÎÀûÀýÇÏ°Ô ¼³Á¤µÈ °æ¿ì, À͸íÀÇ »ç¿ëÀÚµéÀº ID ¿Í ÆÐ½º¿öµå¸¦ ÅëÇÑ ÀÎÁõ°úÁ¤À» °ÅÄ¡Áö ¾Ê°í FrontPage Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥(FP2000 µî)À» »ç¿ëÇØ¼ Á÷Á¢ À¥ ÆäÀÌÁö¿¡ Á¢±ÙÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© Á÷Á¢ À¥ ÆäÀÌÁö¸¦ »èÁ¦Çϰųª °Ô½ÃÇÏ´Â µîÀÇ ¾ÇÀÇÀûÀÎ ÇàÀ§¸¦ ¼öÇàÇÒ ¼ö ÀÖÀ¸¸ç, ³ª¾Æ°¡ À¥ »çÀÌÆ®¿¡ ¼Õ»óÀ» ÀÔÈú ¼öµµ ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/1998_2/0181.html http://www.securityspace.com/smysecure/catid.html?id=11455
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft FrontPage server extension ¸ðµç ¹öÀü |
| ÇØ°áÃ¥ |
ForntPage Server Extensions ÀÇ ±ÇÇÑ ¼³Á¤À» ¿Ã¹Ù¸£°Ô º¯°æÇØ¾ß ÇÑ´Ù. À͸íÀÇ Á¢±ÙÀ» ¸·°í ID ¿Í ÆÐ½º¿öµå¸¦ ÅëÇÑ Àΰ¡µÈ Á¢±Ù¸¸À» Çã¿ëÇØ¾ß ÇÑ´Ù. 1. IIS °ü¸® ÄܼÖÀ» ¿¬´Ù. 2. ±âº» À¥ »çÀÌÆ®ÀÇ "_vti_bin" µð·ºÅ丮¿¡¼ /_vti_auth/author.dll ¿Í /_vti_admin/admin.dll ÆÄÀÏÀ» ¼±ÅÃÇÑ´Ù. 3. ÆÄÀÏÀÇ "µî·ÏÁ¤º¸"¸¦ ¼±ÅÃÇÑ´Ù. 4. "ÆÄÀÏ º¸¾È" ÅÇÀ» ¼±ÅÃÇÑ ÈÄ ÀÍ¸í ¾×¼¼½º ¹× ÀÎÁõ Á¦¾î ÀÇ "ÆíÁý" ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 5. "ÀÍ¸í ¾×¼¼½º" »óÀÇ Ã¼Å© Ç¥½Ã¸¦ Á¦°ÅÇÑ´Ù. 6. ±âº» À¥ »çÀÌÆ®¿¡¼ "Server Extensions °ü¸®ÀÚ" ¸Þ´º¸¦ ÅëÇØ »õ·Î¿î »ç¿ëÀÚ¸¦ Ãß°¡ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
3682 (ISS) |
|