English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22191
À§Çèµµ 40
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WWW
»ó¼¼¼³¸í ÇØ´ç FrontPage Server Extensions¿¡´Â ±ÇÇÑÀÌ ºÎÀûÀýÇÏ°Ô ¼³Á¤µÇ¾î ÀÖ´Ù.
FrontPage Sever Extensions´Â µðÆúÆ®·Î Internet Information Server(IIS) ¼­¹ö¿Í ÇÔ²² ¼³Ä¡µÇ¸ç, À¥ °ü¸®ÀÚ³ª °³¹ßÀÚµéÀÌ FrontPage Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥(FrontPage 2000)À» ÅëÇØ¼­ Á÷Á¢ À¥ ÆäÀÌÁö¸¦ ÀÛ¼ºÇÏ°í ¼­¹ö¸¦ °ü¸®ÇÒ ¼ö ÀÖ´Â ±â´ÉÀ» Á¦°øÇÑ´Ù. FrontPage sever extensions ÀÌ ¼³Ä¡µÈ ¼­¹ö¿¡´Â ¼¼ °¡Áö ÆÄÀÏ, Áï "shtml.dll", "_vti_adm\admin.dll", ±×¸®°í "_vti_aut\author.dll" ÆÄÀϵéÀÌ "_vti_bin" µð·ºÅ丮¿¡ »ý¼ºµÈ´Ù. "admin.dll", "author.dll" °ú °°Àº extension ÆÄÀÏÀº º¸¾ÈÀ» À§ÇØ Àΰ¡µÈ »ç¿ëÀÚµé(À¥ °ü¸®ÀÚ, °³¹ßÀÚ)¿¡°Ô¸¸ Á¢±Ù ±ÇÇÑÀÌ Çã¿ëµÇ¾î¾ß ÇÑ´Ù. ÇÏÁö¸¸, FrontPage Server Extensions »ó¿¡ Á¢±Ù ±ÇÇÑ ¼³Á¤ÀÌ ºÎÀûÀýÇÏ°Ô ¼³Á¤µÈ °æ¿ì, À͸íÀÇ »ç¿ëÀÚµéÀº ID ¿Í ÆÐ½º¿öµå¸¦ ÅëÇÑ ÀÎÁõ°úÁ¤À» °ÅÄ¡Áö ¾Ê°í FrontPage Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥(FP2000 µî)À» »ç¿ëÇØ¼­ Á÷Á¢ À¥ ÆäÀÌÁö¿¡ Á¢±ÙÇÒ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© Á÷Á¢ À¥ ÆäÀÌÁö¸¦ »èÁ¦Çϰųª °Ô½ÃÇÏ´Â µîÀÇ ¾ÇÀÇÀûÀÎ ÇàÀ§¸¦ ¼öÇàÇÒ ¼ö ÀÖÀ¸¸ç, ³ª¾Æ°¡ À¥ »çÀÌÆ®¿¡ ¼Õ»óÀ» ÀÔÈú ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/1998_2/0181.html
http://www.securityspace.com/smysecure/catid.html?id=11455

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft FrontPage server extension ¸ðµç ¹öÀü
ÇØ°áÃ¥ ForntPage Server Extensions ÀÇ ±ÇÇÑ ¼³Á¤À» ¿Ã¹Ù¸£°Ô º¯°æÇØ¾ß ÇÑ´Ù. À͸íÀÇ Á¢±ÙÀ» ¸·°í ID ¿Í ÆÐ½º¿öµå¸¦ ÅëÇÑ Àΰ¡µÈ Á¢±Ù¸¸À» Çã¿ëÇØ¾ß ÇÑ´Ù.
1. IIS °ü¸® ÄܼÖÀ» ¿¬´Ù.
2. ±âº» À¥ »çÀÌÆ®ÀÇ "_vti_bin" µð·ºÅ丮¿¡¼­ /_vti_auth/author.dll ¿Í /_vti_admin/admin.dll ÆÄÀÏÀ» ¼±ÅÃÇÑ´Ù.
3. ÆÄÀÏÀÇ "µî·ÏÁ¤º¸"¸¦ ¼±ÅÃÇÑ´Ù.
4. "ÆÄÀÏ º¸¾È" ÅÇÀ» ¼±ÅÃÇÑ ÈÄ ÀÍ¸í ¾×¼¼½º ¹× ÀÎÁõ Á¦¾î ÀÇ "ÆíÁý" ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
5. "ÀÍ¸í ¾×¼¼½º" »óÀÇ Ã¼Å© Ç¥½Ã¸¦ Á¦°ÅÇÑ´Ù.
6. ±âº» À¥ »çÀÌÆ®¿¡¼­ "Server Extensions °ü¸®ÀÚ" ¸Þ´º¸¦ ÅëÇØ »õ·Î¿î »ç¿ëÀÚ¸¦ Ãß°¡ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 3682 (ISS)