English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26041
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í 'À©µµ¿ìÁî ÄÄÆ÷³ÍÆ® ntdll.dll¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì'¿¡ ´ëÇÑ HotFix (Q815021)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. °æ·Î¸í Àüȯ ÇÔ¼ö¿¡ ÀÖ´Â ¿À¹öÇ÷οì´Â NtDLL³»¿¡ ÀÖÀ¸¸ç, ÀÌ ÇÔ¼ö´Â Kernel32 ¶óÀ̺귯¸®ÀÇ °øÅë API ·ÎºÎÅÍ È£ÃâµÈ´Ù. ÀÌ ¹®Á¦¸¦ °¡Áø ƯÁ¤ API´Â IIS 5.0ÀÇ WebDAV ÄÄÆ÷³ÍÆ®¸¦ ÅëÇØ Á¢±ÙÇÒ ¼ö ÀÖ´Ù. ÀÌ API´Â Windows XP ȤÀº Windows Server 2003 »ó¿¡¼­´Â Ãë¾àÇÏÁö ¾ÊÀº °ÍÀ¸·Î ³ªÅ¸³­´Ù. IIS 4.0Àº µðÆúÆ®·Î WebDAV¸¦ »ç¿ëÇÏÁö ¾Ê´Â´Ù. RFC 2518¿¡ Á¤ÀǵǾî ÀÖ´Â WebDAV´Â ÀÎÅͳݻ󿡼­ ÄÄÇ»Å͵鰣¿¡ ÆíÁý°ú ÆÄÀϰü¸®¿¡ ´ëÇÑ Ç¥ÁØÀ» Á¦°øÇÏ´Â HTTP (Hyper Text Transfer Protocol)¿¡ ´ëÇÑ È®Àå ¼ÂÀÌ´Ù. WebDAV°¡ ÀÛµ¿ÇÏ´Â IIS 5.0 ¼­¹ö·Î Àß Á¶ÀÛµÈ ¿äûÀ» º¸³¿À¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Local System ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇà½Ãų ¼ö ÀÖÀ¸¸ç ½Ã½ºÅÛ¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î±ÇÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù.

¶Ç ÇϳªÀÇ ¹®Á¦´Â 'ntdll.dll'¿¡ ¼ÓÇØ ÀÖ°í ¸î¸î APIµéÀ» ÅëÇØ È£ÃâµÇ´Â 'RtlGetFullPathName_U' ÇÔ¼ö¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ´Ù. °á°úÀûÀ¸·Î ·ÎÄà °ø°ÝÀÚµéÀÌ 65536 ¹ÙÀÌÆ® ÀÌ»óÀÇ »çÀÌÁ °¡Áø ¹®ÀÚ¿­À» °¡Áö°í 'RtlGetFullPathName_U'¸¦ È£ÃâÇÒ ¼ö ÀÖ´Â ÇÁ·Î±×·¥À̳ª ¼­ºñ½ºµéÀ» ¸¸µé ¼ö ÀÖ´Ù¸é °ø°ÝÀÚ´Â ±ÇÇÑÀ» »ó½ÂÇϰųª ÀÓÀÇÀÇ ÄÚµåµéÀ» ½ÇÇà½ÃŰ´Â °ÍÀÌ °¡´ÉÇÏ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms03-007.asp
http://www.cert.org/advisories/CA-2003-09.html
http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0144.html
http://archives.neohapsis.com/archives/bugtraq/2003-06/0005.html
http://www.securityfocus.com/archive/1/323508

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft IIS 5.0
Windows NT 4.0 ¸ðµç ¹öÀü
Windows 2000 ¸ðµç ¹öÀü
Windows XP ¸ðµç ¹öÀü
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS03-007À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡ ('Q815021'ÀÇ Hotfix)¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms03-007.asp

Àӽà Á¶Ä¡¹æ¹ýµé:

¸¸¾à WebDAVÀÇ »ç¿ëÀÌ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ½Ã½ºÅÛÀ¸·ÎºÎÅÍ ÀÛµ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù. WebDAV¸¦ ÀÛµ¿ÁßÁö ½Ã۱â À§Çؼ­´Â:

1. IIS lockdown ÅøÀ» ÀÌ¿ëÇ϶ó. ÀÌ ÅøÀ» ´ÙÀ½ »çÀÌÆ®¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù:
http://www.microsoft.com/download/en/details.aspx?id=25064

2. ¶Ç ´Ù¸¥ ¹æ¹ýÀ¸·Î, MicrosoftÀÇ Knowledgebase Article 241520, "How to Disable WebDAV for IIS 5.0"¿¡ ÀÖ´Â ¸í·ÉµéÀ» µû¸§À¸·Î½á ÀÛµ¿ÁßÁö ½Ãų ¼ö ÀÖ´Ù:
http://support.microsoft.com/default.aspx?scid=kb;en-us;241520

PUT°ú DELETE ¿äûÀ» Æ÷ÇÔÇÏ¿© WebDAV¸¦ ¿ÏÀüÈ÷ Disable ½Ã۱â À§Çؼ­ ·¹Áö½ºÆ®¸®¿¡¼­ ´ÙÀ½°ú °°Àº ¼öÁ¤À» °¡ÇÏ¿©¾ß ÇÑ´Ù.

1) ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ½ÃÀÛÇÑ´Ù. (Regedt32.exe).
2) ·¹Áö½ºÆ®¸®¿¡¼­ ´ÙÀ½ ۸¦ ã¾Æ Ŭ¸¯ÇÑ´Ù:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters

3) ÆíÁý ¸Þ´º¿¡¼­ °ª Ãß°¡¸¦ Ŭ¸¯ÇÏ°í ´ÙÀ½ ·¹Áö½ºÆ®¸® °ªÀ» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù:
°ª À̸§: DisableWebDAV
µ¥ÀÌÅÍ À¯Çü: DWORD
°ª µ¥ÀÌÅÍ: 1

3. ¶ÇÇÑ URLScanÀ» »ç¿ëÇÒ ¼ö Àִµ¥ ÀÌ´Â 'PROPFIND' ¸Þ½îµå¿¡ ´ëÇÑ À¥ ¿äûµéÀ» Â÷´ÜÇÒ ¼ö ÀÖ´Ù. URLScan¿¡ ´ëÇÑ Á¤º¸´Â ´ÙÀ½ »çÀÌÆ®¿¡¼­ ÀÌ¿ë °¡´ÉÇÏ´Ù:
http://support.microsoft.com/default.aspx?scid=kb;[LN];326444

-- ȤÀº --

¸¸¾à IIS lockdown ÅøÀ̳ª URLScan µÑ´Ù »ç¿ëÇÒ ¼ö ¾ø´Ù¸é MicrosoftÀÇ URL Buffer Size Registry ÅøÀ» ÀÌ¿ëÇÏ¿© IIS°¡ ¿äûµéÀ» ó¸®Çϴµ¥ »ç¿ëÇÏ´Â ¹öÆÛÀÇ Å©±â¸¦ Á¦ÇÑÇÏ´Â ¹æ¾ÈÀÌ ÀÖ´Ù. ÀÌ ÅøÀº Windows 2000 Service Pack 2³ª Service Pack 3ÀÌ ¼³Ä¡µÈ ·ÎÄà ȤÀº ¿ø°ÝÁöÀÇ Windows 2000 ½Ã½ºÅÛ¿¡ ´ëÇØ »ç¿ëÇÒ ¼ö ÀÖ´Ù. »ç¿ë¹ý°ú ¼öµ¿À¸·Î ·¹Áö½ºÆ®¸®¿¡ ¼öÁ¤À» °¡ÇÏ´Â ¹æ¹ý¿¡ °üÇÑ ¸í·ÉµéÀº ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¸é µÈ´Ù:

URL Buffer Size Registry Tool - http://go.microsoft.com/fwlink/?LinkId=14875
Microsoft Knowledge Base Article 816930 - http://support.microsoft.com/default.aspx?scid=kb;en-us;816930
Microsoft Knowledge Base Article 260694 - http://support.microsoft.com/default.aspx?scid=kb;en-us;260694
°ü·Ã URL CVE-2003-0109 (CVE)
°ü·Ã URL 7116 (SecurityFocus)
°ü·Ã URL 11533 (ISS)