|
Á¦¸ñ |
MSÀ©µµ¿ì XSS°ø°Ý °¡´ÉÇÑ Á¦·Îµ¥ÀÌ ÁÖÀÇ |
Á¶È¸¼ö |
2,844°Ç |
¡à °³¿ä
o MicrosoftÞäÀÇ(ÀÌÇÏ MS) À©µµ¿ì¿¡¼ MHTMLÀ» ÀÌ¿ëÇÏ¿© Á¤º¸¸¦ À¯Ãâ ½Ãų ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ ¹ß°ßµÊ[1]
o °ø°ÝÀÚ´Â À¥ ÆäÀÌÁö Àº´Ð, ½ºÆÔ ¸ÞÀÏ, ¸Þ½ÅÀúÀÇ ¸µÅ© µîÀ» ÅëÇØ Æ¯¼öÇÏ°Ô Á¶ÀÛµÈ À¥ÆäÀÌÁö¸¦ »ç¿ëÀÚ°¡ ¿¾îº¸µµ·Ï À¯µµÇÏ¿© ¾Ç¼º ½ºÅ©¸³Æ® ½ÇÇà°ú Á¤º¸À¯Ãâ °¡´É
¡Ø XSS(Cross-Site Script)°ø°Ý°ú À¯»çÇÑ È¿°ú¸¦ °¡Áü
o ÇØ´ç Ãë¾àÁ¡ÀÇ °³³äÁõ¸íÄÚµå[2]°¡ °ø°³µÇ¾úÀ¸¹Ç·Î, ½Å·ÚÇÒ ¼ö ¾ø´Â À¥ÆäÀÌÁö¸¦ ¿¾îº¸Áö ¾Ê´Â µîÀÇ »ç¿ëÀÚ ÁÖÀÇ°¡ ¿ä±¸µÊ
¡à ¿µÇâ ¹Þ´Â ½Ã½ºÅÛ
o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î [1]
- Windows XP Service Pack 3, x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2, x64 Edition Service Pack 2, SP2 for Itanium-based Systems
- Windows Vista Service Pack 1 and Windows Vista Service Pack 2, x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit, 64-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2**
- Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2**
- Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
- Windows 7 for 32-bit, 64-bit Systems
- Windows Server 2008 R2 for x64-based Systems**
- Windows Server 2008 R2 for Itanium-based Systems
¡Ø **Ç¥½ÃµÈ À©µµ¿ì¸¦ ¼¹öÄÚ¾î(Server Core)¿É¼ÇÀ¸·Î ¼³Ä¡ÇÑ °æ¿ì, ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹ÞÁö ¾ÊÀ½
¡à ±ÇÀå ¹æ¾È
o ÇöÀç ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ®´Â ¹ßÇ¥µÇÁö ¾Ê¾ÒÀ½
o Ãë¾àÁ¡À¸·Î ÀÎÇÑ À§ÇùÀ» °æ°¨½ÃÅ°±â À§ÇØ ´ÙÀ½°ú °°Àº Á¶Ä¡¸¦ ±ÇÀåÇÔ[3]
- MS ȨÆäÀÌÁö ¡°Fix it for me¡±¼½¼ÇÀÇ ¡°Microsoft Fix it 50602¡±¸¦ ´Ù¿î·Îµå ÈÄ ¼³Ä¡
¡Ø ¿ø»óÅ·Πº¹±¸Çϱâ À§Çؼ´Â ¡°Microsoft Fix it 50603¡±À» Àû¿ë
¡Ø ÇØ´ç Á¶Ä¡·Î ÀÎÇØ MHTMLÆäÀÌÁö¸¦ º¼ ¼ö ¾øÀ½À¸·Î ÁÖÀÇ°¡ ÇÊ¿äÇÔ
o KrCERT/CC¿Í MS º¸¾È¾÷µ¥ÀÌÆ® »çÀÌÆ®[4]¸¦ ÁÖ±âÀûÀ¸·Î È®ÀÎÇÏ¿© ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ® ¹ßÇ¥ ½Ã ½Å¼ÓÈ÷ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇϰųª ÀÚµ¿¾÷µ¥ÀÌÆ®¸¦ ¼³Á¤
¡Ø ÀÚµ¿¾÷µ¥ÀÌÆ® ¼³Á¤ ¹æ¹ý: ½ÃÀÛ¡æÁ¦¾îÆǡ溸¾È¼¾ÅÍ¡æÀÚµ¿¾÷µ¥ÀÌÆ®¡æÀÚµ¿(±ÇÀå) ¼±ÅÃ
o Ãë¾àÁ¡¿¡ ÀÇÇÑ ÇÇÇظ¦ ÁÙÀ̱â À§ÇÏ¿© »ç¿ëÀÚ´Â ´ÙÀ½°ú °°Àº »çÇ×À» ÁؼöÇØ¾ß ÇÔ
- ÆÄÀÏ°øÀ¯ ±â´É µîÀ» »ç¿ëÇÏÁö ¾ÊÀ¸¸é ºñÈ°¼ºÈÇÏ°í °³ÀιæȺ®À» ¹Ýµå½Ã »ç¿ë
- »ç¿ëÇÏ°í ÀÖ´Â ¹é½ÅÇÁ·Î±×·¥ÀÇ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ À¯ÁöÇÏ°í, ½Ç½Ã°£ °¨½Ã±â´ÉÀ» È°¼ºÈ
- ½Å·ÚµÇÁö ¾Ê´Â À¥ »çÀÌÆ®ÀÇ ¹æ¹® ÀÚÁ¦
- Ãâó°¡ ºÒºÐ¸íÇÑ À̸ÞÀÏÀÇ ¸µÅ© Ŭ¸¯Çϰųª ÷ºÎÆÄÀÏ ¿¾îº¸±â ÀÚÁ¦
¡à ¿ë¾î Á¤¸®
o MHTML : HTMLÀ¥ÆäÀÌÁö°¡ ÂüÁ¶ÇÏ´Â º°µµÀÇ ÆÄÀÏ(±×¸², À½¼º µî)À» ÀÎÄÚµùÇÏ¿© ÇØ´ç À¥ÆäÀÌÁö ÆÄÀÏ¿¡ Æ÷ÇÔ½ÃŲ ±â¼ú
o XSS(Cross-Site Script) : À¥ ¾ÖÇø®ÄÉÀÌ¼Ç Ãë¾àÁ¡À¸·Î À¥»çÀÌÆ® °ü¸®ÀÚ°¡ ¾Æ´Ñ ÀÌ°¡ À¥ ÆäÀÌÁö¿¡ ¾Ç¼º ½ºÅ©¸³Æ®¸¦ »ðÀÔÇÏ¿© ´Ù¸¥ »ç¿ëÀÚ°¡ À̸¦ ½ÇÇàÇϵµ·Ï Çã¿ëÇÏ´Â Ãë¾àÁ¡
[Âü°í»çÀÌÆ®]
[1] http://www.microsoft.com/technet/security/advisory/2501696.mspx
[2] http://www.exploit-db.com/exploits/16071/
[3] http://support.microsoft.com/kb/2501696
[4] http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=ko
|
|