| Ãë¾àÁ¡ID |
22206 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
80, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
WWW |
| »ó¼¼¼³¸í |
ÇØ´ç iisPROTECT¿¡´Â SQL Injection Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. iisPROTECT´Â À¥ ÆäÀÌÁöµéÀ» ÆÐ½º¿öµå·Î º¸È£Çϱâ À§ÇØ »ç¿ëµÇ´Â À¥ ±â¹ÝÀÇ »ç¿ëÀÚ ÀÎÁõ ÇÁ·Î±×·¥À¸·Î MS Windows Ç÷§Æû »ó¿¡¼ µ¿ÀÛÇÑ´Ù. MS access ÆÄÀÏ ¶Ç´Â MS SQL ¼¹ö¸¦ ±âº»Àû DB ·Î »ç¿ëÇÑ´Ù. iisPROTECT´Â À¥ °ü¸®ÀÚ ÀÎÅÍÆäÀ̽º(SiteAdmin.asp) »ó¿¡¼ »ç¿ëÀÚ ÀÔ·ÂÀ» ÀûÀýÈ÷ ÇÊÅ͸µÇÏÁö ¸øÇÏ´Â ¹®Á¦·Î ÀÎÇÏ¿©, SQL Injection °ø°Ý¿¡ Ãë¾àÇÏ´Ù. 'GroupName'°ú °°Àº ƯÁ¤ º¯¼ö ³»¿¡ ÀÓÀÇÀÇ SQL Äڵ带 »ðÀÔÇÏ¿© SiteAdmin.asp ½ºÅ©¸³Æ® ¿äûÀ» ÇÔÀ¸·Î½á, ¿ø°ÝÁö °ø°ÝÀÚµéÀº ÈÄÀ§(backend)ÀÇ µ¥ÀÌÅͺ£À̽º¿¡ Á¤º¸¸¦ Ãß°¡, »èÁ¦, º¯°æÇÒ ¼ö ÀÖ´Ù. ´ÙÀ½Àº 'xp_cmdshell' store procedure ¸¦ ½ÇÇàÇÏ¿© ¿ø°ÝÁö È£½ºÆ®ÀÇ ¿î¿µÃ¼Á¦ »óÀÇ Ping ¸í·ÉÀ» ½ÇÇàÇÏ´Â ¿¹ÀÌ´Ù.
http://www.example.com/iisprotect/admin/SiteAdmin.ASP?V_SiteName=&V_FirstTab=Groups&V_SecondTab=All&GroupName=secuiscan';exec%20master..xp_cmdshell'ping%2010.10.10.11';--
* Âü°í »çÀÌÆ®: http://www.securiteam.com/windowsntfocus/5GP0M1PA0K.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: iisPROTECT 2.2-r4 |
| ÇØ°áÃ¥ |
´ÙÀ½ ¸µÅ©¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ iisPROTECT·Î ¾÷±×·¹À̵åÇÒ °ÍÀ» ±Ç°íÇÑ´Ù. http://www.iisprotect.com/ |
| °ü·Ã URL |
CVE-2003-0377 (CVE) |
| °ü·Ã URL |
7675 (SecurityFocus) |
| °ü·Ã URL |
12065 (ISS) |
|