| Ãë¾àÁ¡ID |
23041 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
7100 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
IRCXPRO |
| »ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â IRCXPro°¡ µ¿ÀÛ ÁßÀÌ¸ç ·Î±×ÀÎ °¡´ÉÇÑ µðÆúÆ® ID, ÆÐ½º¿öµå°¡ Á¸ÀçÇÑ´Ù. IRCXPro ¼¹ö´Â Microsoft Windows Ç÷§Æû »ó¿¡¼ µ¿ÀÛÇÏ´Â ¹«·á ÀÎÅÍ³Ý Relay-Chat ¼¹ö ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ÇÁ·Î±×·¥Àº Ãʱ⠵ðÆúÆ® ¼³Ä¡ ½Ã, ¿ø°Ý °ü¸®ÀÚ ¼³Á¤À» À§ÇØ µðÆúÆ®·Î ID¿Í ÆÐ½º¿öµå, "admin:password" ¸¦ »ý¼ºÇÑ´Ù. µðÆúÆ® ID¿Í ÆÐ½º¿öµå°¡ ±×·¡µµ ¹æÄ¡µÉ °æ¿ì, ÀÌ Ãë¾àÁ¡À» µµ¿ëÇÏ¿© ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¼¹ö¿¡ ´ëÇÑ ºñÀΰ¡µÈ °ü¸®ÀÚ ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2003-06/0015.html
* ¿µÇâÀ» ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î: IRCXPro Server 1.0 |
| ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽйöÀüÀÇ IRCXPro·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù. http://ircxpro.soft32download.com/
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î, 1. ½ÃÀÛ ¸Þ´º¿¡¼ IRCXPro ¼³Á¤ ÀÎÅÍÆäÀ̽ºÀÎ "IRCXPro" ¸¦ ¿¬´Ù. 2. "Operator" ¸Þ´º¸¦ ¼±ÅÃÇÑ ÈÄ ¿î¿µÀÚ À̸§ "admin" À» ¼±ÅÃÇÑ´Ù. 3. "Delete Operator" ¹öưÀ» »ç¿ëÇØ¼ ¿î¿µÀÚ¸¦ »èÁ¦ÇÑ ÈÄ "Add Operator" ¹öưÀ» ÅëÇØ »õ·Î¿î °ü¸®ÀÚ °èÁ¤À» »ý¼ºÇÑ´Ù. 4. ¶Ç´Â, "Editor Operator" ¹öưÀ» ÅëÇØ "admin" °èÁ¤¿¡ ´ëÇÑ µðÆúÆ® ÆÐ½º¿öµå(password)¸¦ ÃßÃøÇϱ⠾î·Á¿î °ÍÀ¸·Î º¯°æÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
12168 (ISS) |
|