Ãë¾àÁ¡ID |
27070 |
À§Çèµµ |
10 |
Æ÷Æ® |
135 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
WMI |
»ó¼¼¼³¸í |
»ç¿ëÇÏÁö ¾Ê´Â ½ºÅ©¸³Æ® ¸ÅÇÎÀº º¸¾È¿¡ À§ÇùÀÌ µÉ ¼ö ÀÖÀ¸¹Ç·Î °³¹ßÀÚ¿Í ÇùÀÇÇÏ¿© ºÒÇÊ¿äÇÑ ¸ÅÇÎÀÎÁö È®ÀÎÇÑ ÈÄ Á¦°ÅÇÔ. .asp³ª .shtm °ú °°Àº È®ÀåÀÚµéÀº ƯÁ¤ DLL ÆÄÀÏ°ú ¸ÅÇÎ µÇ¾î ÀÖ¾î, ÀÌ·¯ÇÑ ÆÄÀϵ鿡 ´ëÇÑ ¿äûÀÌ µé¾î¿À¸é ÇØ´ç DLL¿¡ ÀÇÇØ Ã³¸®µÊ. ÀÌ·¯ÇÑ ¸ÅÇÎ Áß »ç¿ëµÇÁö ¾Ê´Â °ÍµéÀº Á¦°ÅÇÏ¸é º¸¾È¿¡ µµ¿òÀÌ µÇ¸ç, ƯÈ÷, .ida, .idc, .idq, .printer, .htr, .htw È®ÀåÀÚ´Â ¹öÆÛ ¿À¹öÇ÷οì(Buffer Overflow) °ø°Ý À§ÇèÀÌ Á¸ÀçÇϹǷΠ»èÁ¦¸¦ ±Ç°íÇÔ
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft IIS Server |
ÇØ°áÃ¥ |
¡á IIS 5.0, 6.0
1. ½ÃÀÛ> ½ÇÇà> INETMGR> À¥ »çÀÌÆ®> ÇØ´ç À¥ »çÀÌÆ®> ¼Ó¼º> [Ȩ µð·ºÅ͸®] ÅÇ¿¡¼ [±¸¼º] ¹öÆ° ¼±ÅÃ
2. [¸ÅÇÎ] ÅÇ¿¡¼ ¾Æ·¡¿Í °°Àº Ãë¾àÇÑ ¸ÅÇÎ Á¦°Å
(.asp, .htr, .stm, .shtm, .shtml, .printer, .htw, .ida, .idq, .htw)
È®ÀåÀÚ¸í ±â´É Ãë¾àÁ¡
-------------------------------------------------------------------------------------------------
asp -> Active Server Pages ±â´É Áö¿ø Buffer Overflow (MS02-018)
win 2000 SP3 ÀÌ»ó ¾çÈ£
-------------------------------------------------------------------------------------------------
htr -> web-based password reset +.htr ¼Ò½º °ø°³ Ãë¾àÁ¡
Outlook Web Access µî¿¡¼ À¥ ±â¹Ý ÀÀ¿ë (MS01-004)
ÇÁ·Î±×·¥À¸·Î ÀÚ½ÅÀÇ »ç¿ëÀÚ °èÁ¤ ¾ÏÈ£ º¯°æ win2000 SP3, NT SP 7.0ÀÌ»ó
¾çÈ£
-------------------------------------------------------------------------------------------------
idc -> Internet Database Connector Web µð·ºÅ͸® Æнº °ø°³
SQL ¼¹ö¿¡ ¿¬°áÇϱâ À§ÇÑ Á¤º¸ µîÀ» (Q193689)
°ü¸®ÇÔ. asp¸¦ ÅëÇØ °°Àº ÀÛ¾÷À» ¼öÇà °¡´É NT4.0 NT SP6a ÀÌ»ó ¾çÈ£
-------------------------------------------------------------------------------------------------
stm, stml, -> Server-Side Includes Buffer Overflow (MS01-044)
shtml Win 2000 SP3 ÀÌ»ó ¾çÈ£
-------------------------------------------------------------------------------------------------
printer -> Internet Printing : URLÀ» »ç¿ëÇÏ¿© Buffer Overflow (MS01-023)
ÆäÀÌÁö¸¦ ÇÁ¸°ÅÍ·Î ÀμâÇÒ ¼ö ÀÖµµ·Ï ÇÔ Win 2000 SP2 ÀÌ»ó ¾çÈ£
IIS°¡ ÀÎÅͳÝÀ̳ª ÀÎÆ®¶ó³ÝÀ» ÅëÇØ Àμâ
¼¹ö ±â´É ¼öÇà
--------------------------------------------------------------------------------------------------
ida, idq -> Index Server : idq.dll¿¡ ¸ÅÇεǸç À妽º Buffer Overflow MS01-033
¼¹ö¸¦ Äõ¸®ÇÒ ¶§ »ç¿ë Win 2000 SP3 ÀÌ»ó ¾çÈ£
--------------------------------------------------------------------------------------------------
htw -> Index Server : webhits.dll¿¡ ¸ÅÇεǸç, Webhit ¼Ò½º °ø°³ Ãë¾àÁ¡
À妽º ¼¹ö¸¦ Äõ¸®ÇÒ ¶§ »ç¿ë (MS00-006)
Win 2000 SP1 ÀÌ»ó ¾çÈ£
--------------------------------------------------------------------------------------------------
¡á IIS 7.0
1, 8.0, 10.0 ½ÃÀÛ> ½ÇÇà> INETMGR> À¥ »çÀÌÆ®> ÇØ´ç À¥ »çÀÌÆ®> 󸮱⠸ÅÇÎ ¼±ÅÃ
2. Ãë¾àÇÑ ¸ÅÇÎ Á¦°Å(.htr, .idc, .stm, .³ë½º, .shtml, .printer, .htw, .ida, .idq) |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|