¾È³çÇϽÃÁ¶ ?
ºñ¾¾ÆÄÅ© ¼·Áö±â Á¶°æÈñÀÔ´Ï´Ù. ^_______^ (8)(8)
¾È³çÇϼ¼¿ä. Çѱ¹Á¤º¸º¸È£ÁøÈï¿øÀÔ´Ï´Ù.
MS À©µµ¿ìÁî Ä¿³Î¿¡ Á¸ÀçÇÏ´Â ½ºÅà ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù.
º¸¾È ¾÷¹«¿¡ Âü°íÇÏ½Ã±æ ¹Ù¶ø´Ï´Ù.
================================================================
KA-2003-27: Microsoft Windows kernel contains stack overflow
----------------------
ÃÖÃÊÀÛ¼ºÀÏ : 2003-04-16
°» ½Å ÀÏ : 2003-04-16
Ãâ ó : //www.kb.cert.org/vuls/id/446338
ÀÛ ¼º ÀÚ : ±è°æÈñ(khkim@certcc.or.kr)
-- Á¦¸ñ --------------
Microsoft Windows Ä¿³Î¿¡ Á¸ÀçÇÏ´Â ½ºÅà ¿À¹öÇ÷οì Ãë¾àÁ¡
-- ÇØ´ç ½Ã½ºÅÛ --------
Microsoft Windows NT 4.0
Microsoft Windows NT 4.0 Server, Terminal Server Edition
Microsoft Windows 2000
Microsoft Windows XP
--¿µÇâ-----------------
Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÀÚ°¡ ¿î¿µÃ¼Á¦ÀÇ Ä¿³Î¿µ¿ª¿¡ ÄÚµå ¼öÇàÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù.
Áï, °ø°ÝÀÚ´Â Ä¿³ÎÀÌ ÇÒ ¼ö ÀÖ´Â ¸ðµç ±ÇÇÑ(½Ã½ºÅÛ ¸Þ¸ð¸®ÀÇ º¸È£¿µ¿ª Àбâ, µð½ºÅ©¿¡ ¾²±â, ³×Æ®¿öÅ©°£ÀÇ Åë½Åµî)À» °¡Áö°Ô µÇ´Â °ÍÀÌ´Ù.
-- ÇØ°áÃ¥--------------------------
ÆÐÄ¡¸¦ Àû¿ëÇÑ´Ù.
ÆÐÄ¡ ´Ù¿î·Îµå À§Ä¡ :
o Windows NT 4.0
//microsoft.com/downloads/details.aspx?FamilyId=C3596ED1-596F-416C-8BE5-91AE65619A1A&displaylang=en
o Microsoft Windows NT 4.0 Server, Terminal Server Edition
//microsoft.com/downloads/details.aspx?FamilyId=910A0015-3723-4A4E-9049-99A4CE52B5F8&displaylang=en
o Microsoft Windows 2000
//microsoft.com/downloads/details.aspx?FamilyId=CACAC8C0-81E9-413E-B565-5D7B3257A733&displaylang=en
oMicrosoft Windows XP
//microsoft.com/downloads/details.aspx?FamilyId=9F81E615-3DEC-4A4B-826A-4E0FEAB42323&displaylang=en
//microsoft.com/downloads/details.aspx?FamilyId=DBC47904-51C8-475A-9900-3DF363A51A3A&displaylang=en
-- ÂüÁ¶ »çÀÌÆ® --------------------------
//www.kb.cert.org/vuls/id/446338
//www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-013.asp
----------------------------------------------------------------
Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(Korea Information Security Agency),
Computer Emergency Response Team Coordination Center , CERTCC-KR
ÀüÈ: 118 (Áö¹æ 02-118) Email: cert@certcc.or.kr
================================================================
--------------------------------------------------------------------
Kyong Hee Kim
E-mail: khkim@certcc.or.kr
Tel:+82-2-405-5087, Fax:+82-2-405-5519
--------------------------------------------------------------------
* CERTCC-KR Security Incident Report and help desk Contact Points :
cert@certcc.or.kr [Tel]+82-2-118 / [Fax]+82-2-405-5519
{PGP Public Key - //www.certcc.or.kr/teampub.txt}
[Post] 78, Karak dong, Songpa-Gu, Seoul 138-160, Korea
--------------------------------------------------------------------
[Ãßõ] ºñ¾¾ÆÄÅ© Ãʰí¼Ó ¸¶ÀÌȨ È£½ºÆÃ(ÇöÀç ¼³Ä¡ºñ ¹«·áÇà»ç)
¡æ : ¼¹ö Á¢¼Ó¿¡ ÇÊ¿äÇÑ FTP°èÁ¤
¡æ : ÇöÁ¸ÇÏ´Â PHP, CGI, PERLµî¿¡ °Ô½ÃÆÇ ¼³Ä¡ Áö¿ø [°ÅÀÇ ¸ðµç °Ô½ÃÆÇ ¼³Ä¡°¡ °¡´ÉÇÏÁ¶]
¡æ : »ç¿ëÀÚ ÇÁ¶óÀ̹ö½Ã¸¦ Áö۱â À§ÇØ CGIWRAPÀ» Áö¿øÇÕ´Ï´Ù.
¡æ : ½Ã´ë¿¡ ¸Â°Ô ÆÄÀ̽ã°ú ¹«¼±ÀÎÅÍ³Ý WMLÀ» Áö¿øÇÕ´Ï´Ù.
¡æ : ȸ¿ø´Ô¿¡ ¾ÆÀ̵ð·Î ºñ¾¾ÆÄÅ© µµ¸ÞÀÎÀ» µå¸³´Ï´Ù.
¡æ : ºñ¾¾ÆÄÅ© È£½ºÆÃÀº 100Mbpsºü¸¥ ȸ¼±À» »ç¿ëÇÕ´Ï´Ù.
¡æ : ÃÖ°í±Þ¼¹ö ÆæÆ¼¿ò 2.4G¿Í ¸Þ¸ð¸® 1G¸¦ »ç¿ëÇÕ´Ï´Ù.
¡æ : ½ÅûÀÚ¿¡ ÇÑÇØ JSPµµ Áö¿øÇÕ´Ï´Ù.
¡æ : ´Ù¸¥ Þä ¸ÞÀϰú ºñ±³ °ÅºÎ (¿ë·® µÎµÏÇÑ ¸ÞÀÏ °èÁ¤À» µå¸®°í ÀÖ½À´Ï´Ù)
¡æ : ȨÆäÀÌÁö ¶Ç´Â °³¹ßÀÚ¿Í °øºÎ Àǵµ¿¡ ¸Â°Ô Q/A¸¦ ÅëÇÑ ±â¼úÁö¿ø.