¸¶·çÀ¥È£½ºÆà :: À¥È£½ºÆÃ, µµ¸ÞÀÎ µî·Ï, ¼îÇθô È£½ºÆÃ, À̹ÌÁö ¸µÅ©, ¼­¹ö È£½ºÆÃ, ÄÚ·ÎÄÉÀ̼Ç, ¼­¹ö°ü¸®Åø, ¸®¼¿·¯, ȨÆäÀÌÁö Á¦ÀÛ, ¹«·áÈ£½ºÆà Á¦°ø
140-008-011577
 
140-008-011577
ÀÔ±ÝÈ®ÀνÅû ½ÅûÇöȲº¸±â

°í°´Áö¿ø¼¾ÅÍ

1:1 ¹®ÀÇÇϱâ
  • AM 09:00 ~ PM 05:00
  • AM 11:30 ~ PM 01:00

Q&A °Ô½ÃÆÇ



  Á¦·Îº¸µå ¼Ò½º º¯Á¶¿¡ ´ëÇÑ ¾È³» ¸»¾¸.
     2010-12-21 11:27:53 8984 

¡Ø ºü¸¥ 󸮸¦ À§Çؼ­ µµ¸ÞÀÎ ¶Ç´Â  FTP ¾ÆÀ̵𠸦 Àû¾î ÁÖ½Ã±æ ¹Ù¶ø´Ï´Ù.
¡Ø ºü¸¥ 󸮸¦ À§Çؼ­ µµ¸ÞÀÎ ¶Ç´Â  FTP ¾ÆÀ̵𠸦 Àû¾î ÁÖ½Ã±æ ¹Ù¶ø´Ï´Ù.
¾È³çÇϼ¼¿ä. ¸¶·çÀÎÅͳÝÀÔ´Ï´Ù.

12¿ù 18ÀÏ ÀÌÈÄ·Î Á¦·Îº¸µå Ãë¾à¼ºÀ¸·Î ÀÎÇÑ ÆÄÀÏ º¯Á¶°¡ ¹ß»ýÇÏ°í ÀÖ½À´Ï´Ù.

ÇöÀç±îÁö ¹ß»ýÇÑ °æ¿ì¸¦ º¸¸é Á¦·Îº¸µåÀÇ ¹öÀüÀÌ pl8 ÀÌÇÏÀÎ °æ¿ì¿¡
¹ß»ýÇÏ°í ÀÖ½À´Ï´Ù. Á¦·Îº¸µåÀÇ ¹öÀüÀº bbs Æú´õÀÇ lib.php ÆÄÀÏ¿¡¼­
È®ÀÎÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.
_________________________________________________________________________

¿øÀÎ :  Á¦·Îº¸µå 4 °Ô½ÃÆÇÀÇ Ãë¾à¼ºÀ» ÀÌ¿ëÇÑ ÆÄÀÏ º¯Á¶

Áõ»ó  :   1. bbs/icon Æú´õ¿¡ group_qazwsxedc.jpg ÆÄÀÏ°ú visitLog.php »ý¼º

            2. °èÁ¤³» È®ÀåÀÚ°¡ html, php  ÆÄÀϵ鿡 frame src="¾Ç¼ºÄÚµå ¹èÆ÷Áö URL »ðÀÔ (¿¹: http://h.nexprice.com/css/x.htm)

                * ÁÖ·Î bbs/Æú´õ³»ÀÇ ÆÄÀϵ鿡 ¼Ò½º°¡ »ðÀԵ˴ϴÙ.
                * °èÁ¤³» ÆÄÀϵ鿡 iframe »ðÀÔÀº ¾øÀ» ¼öµµ ÀÖ½À´Ï´Ù.
          
            3. Á¦·Îº¸µå DB¿¡ zetyx_group_table »ý¼ºµÇ°í ÀÌ Å×À̺íÀÇ  header ¶Ç´Â
                header_url ¿¡ À§ 2¹ø°ú µ¿ÀÏÇÑ ¾Ç¼ºÄÚµå ¹èÆ÷Áö URL »ý¼º.

2010³â 12¿ù 22ÀÏ RFI Ãë¾àÁ¡ º¸¾È ÆÐÄ¡

1. bbs/icon Æú´õ¿¡ »ý¼ºµÈ group_qazwsxedc.jpg, visitLog.php ÆÄÀÏ »èÁ¦
2. html, php ÆÄÀÏ¿¡ »ðÀÔµÈ iframe ¼Ò½º »èÁ¦
3. °ü¸®ÀÚ ÆäÀÌÁö¸¦ ÅëÇØ qazwsxedc ±×·ì »èÁ¦
4. Á¦·Îº¸µå¼³Ä¡Æú´õ/_head.php ÆÄÀÏÀÇ 13¹ø° ÁÙ ¼Ò½º º¯°æ(°ø½Ä º¸¾È ÆÐÄ¡ ÆäÀÌÁö Âü°í)
5. Á¦·Îº¸µå¼³Ä¡Æú´õ/skin/zero_vote/ask_password.php / error.php / login.php ÆÄÀÏÀÇ 2¹ø° ÁÙ ¼Ò½º °¢°¢ º¯°æ(°ø½Ä º¸¾È ÆÐÄ¡ ÆäÀÌÁö Âü°í)

¡Ø Á¦·Îº¸µå °ø½Ä º¸¾È ÆÐÄ¡
http://www.xpressengine.com/zb4_security/19346851

Á¦·Îº¸µå4 pl9 ¹öÀü¿¡¼­ RFI (¿ø°ÝÆÄÀÏ ÀÎŬ·çµå) Ãë¾àÁ¡ÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù.

Àå°æĨ´Ô²²¼­ Á¦º¸ÇØÁֽŠ³»¿ëÀÔ´Ï´Ù.

_head.php ÆÄÀÏ°ú skin/zero_vote/*.php ÆÄÀÏ¿¡ ´ëÇØ ¾Æ·¡ ³»¿ëÀ¸·Î ÄÚµå ¼öÁ¤À» ÅëÇÑ ÆÐÄ¡¸¦ ±Çµå¸³´Ï´Ù.

_head.php

[¼öÁ¤Àü]

_head.php
view sourceprint?13.if(eregi(":\/\/",$_zb_path)||eregi("\.\.",$_zb_path)||eregi("^\/",$_zb_path)||eregi("data:;",$_zb_path)) $_zb_path ="./";

[¼öÁ¤ÈÄ]

_head.php: ¹®ÀÚ°¡ $_zb_path¿¡ Æ÷ÇÔµÇÁö ¾Êµµ·Ï ¼öÁ¤
view sourceprint?13.if(eregi(":\/\/",$_zb_path)||eregi("\.\.",$_zb_path)||eregi("^\/",$_zb_path)||eregi("data:;",$_zb_path)||eregi(":",$_zb_path)) $_zb_path ="./";


skin/zero_vote/ µð·ºÅ丮ÀÇ ¾Æ·¡¿¡ ÇØ´çµÇ´Â .php ÆÄÀÏ

        - ask_password.php

        - error.php

        - login.php

[¼öÁ¤Àü]

./skin/zero_vote/ask_password.php, error.php, login.php
view sourceprint?2.if(eregi(":\/\/",$dir)||eregi("\.\.",$dir)||eregi("^\/",$dir)||eregi("data:;",$dir)) $dir ="./";

[¼öÁ¤ÈÄ]

./skin/zero_vote/ask_password.php, error.php, login.php
view sourceprint?2.if(eregi(":\/\/",$dir)||eregi("\.\.",$dir)||eregi("^\/",$dir)||eregi("data:;",$dir)||eregi(":",$dir)) $dir ="./";

--------------------------------------------------------------------------------------------
   
_
À§ ³»¿ëÀÇ Á¶Ä¡´Â ±Ùº»ÀûÀÎ Á¶Ä¡´Â ¾Æ´Ï¸ç ¾Ç¼ºÄÚµå ¼Ò½º »ðÀÔ¿¡ ´ëÇÑ ´ëÀÀ Á¶Ä¡·Î
Á¦·Îº¸µå Ãë¾à¼ºÀÌ ÇØ°áµÇÁö ¾ÊÀ¸¸é ¹Ýº¹µÉ ¼ö ÀÖ½À´Ï´Ù. ±×·¯³ª Á¦·Îº¸µå4 °Ô½ÃÆÇÀÇ
°æ¿ì¿¡´Â 2009.09.29ÀÚ·Î Á¦·Îº¸µå4 °ø½Ä ¹èÆ÷°¡ ÁßÁöµÇ¾ú±â ¶§¹®¿¡ ÇØ°áÀÌ µÇÁö ¾Ê½À´Ï´Ù.

À§¿Í °°Àº Á¡À» °í·ÁÇÏ¿© Á¦·Îº¸µå4 °Ô½ÃÆÇ »ç¿ëÀÚ²²¼­´Â xe·ÎÀÇ ¾÷±×·¹À̵峪
Áö¼ÓÀûÀ¸·Î º¸¾È ÆÐÄ¡°¡ °¡´ÉÇÑ °Ô½ÃÆÇÀ¸·ÎÀÇ º¯°æÀ» °í·ÁÇϽñ⠹ٶø´Ï´Ù.





¹Ú¹ÎÈ£
¾îÁ¦µµ ¸îº¯À» ¹®ÀÇ µå·ÈÁö¸¸ À§ ³»¿ëÀº Á¦°¡ ¸ÕÀú ¸µÅ©·Î ¾Ë·Áµå¸°°Å°í¿ä.
¸¶·çÄ«¿îÅÍ ¸¶·çÆ˾÷ ÆÄÀÏ¿¡ ¾Ç¼ºÄÚµå ¼Ò½º »ðÀÔµÈ °ÍÀº ¾î¶»°Ô ÇؾßÇÏ³Ä°í ¸î ¹øÀ» ¹®ÀÇ µå·È´Âµ¥ ´äº¯ÀÌ ¾øÀ¸½Ã³×¿ä.
2010-12-21
 


¾È³çÇϼ¼¿ä ¸¶·çÀÎÅͳÝÀÔ´Ï´Ù.

¸¶·çÄ«¿îÅÍ, ¸¶·çÆ˾÷Àº »èÁ¦ ÇϽŠÈÄ ´Ù½Ã ¼³Ä¡ ÇϽðųª,
ÆäÀÌÁö º¯Á¶½Ã ÃÖÇÏ´Ü¿¡ ¾Ç¼º½ºÅ©¸³Æ®°¡ »ðÀÔ µÇ¿À´Ï, ¼Ò½º ÆÄÀÏÀ» ¿­¾î¼­
¾Ç¼º ½ºÅ©¸³Æ® ºÎºÐ¸¸ »èÁ¦ Çϼż­ ÀÌ¿ë ÇÏ½Ã¸é µË´Ï´Ù.

°¨ »ç ÇÕ ´Ï ´Ù.
2010-12-21
 


14722    [re] ¾ÆÀÌÁðºô´õ ¼³Ä¡½Åû¿ä.. ^^*       2003/12/24 9010
14721    [re] ±¸À±¼­´Ô...       2004/02/23 9008
14720    [re] cool@cooltank.comÀÇ µ¿ÀÛÀº Á¤»óÀÔ´Ï´Ù.;       2003/12/24 9008
14719      [re] ºü¸¥´äº¯ °¨»çµå¸³´Ï´Ù.(³Ã¹«)      Á¤ÁøÈñ 2003/12/13 9006
14718  FTP!      È«Á¤ÈÆ 2004/01/01 8999
14717    [re] ³× ´äº¯ÀÔ´Ï´Ù.       2003/12/30 8999
14716  ³ëµ¿Á¶ÇÕ È¨ÆäÀÌÁö ¸¸µé·Á°í Çϴµ¥      È«ÀºÁ¤ 2003/12/29 8998
14715    °£·«È÷ ´Ù½Ã ¸»¾¸µå¸®¸é.........      ±è½ÃÂù 2003/12/10 8998
14714  ¸¶·çÄ«¿îÅÍ Pro 1.6 ¹èÆ÷¾È³»       2006/10/25 8996
14713    [re] È®ÀÎÀ» ÇÏ´Ï.. ^^;       2003/12/26 8995
14712  ÀԱݿϷáÇß½À´Ï´Ù. ±ÞÇѰŶó ÃÖ´ëÇÑ »¡¸®Ã³¸®ÇØÁÖ¼¼¿ä      ¹Ú¼ºÁø 2003/12/10 8987
 Á¦·Îº¸µå ¼Ò½º º¯Á¶¿¡ ´ëÇÑ ¾È³» ¸»¾¸.  [2]     2010/12/21 8984
14710  µµ¸ÞÀÎ ¸¸·áÀÚÀä, Á¦ ȨÇÇ ÀÚ·á ¹é¾÷À» ¿øÇÕ´Ï´Ù.  [1]    °í½Â¹ü 2008/01/12 8982
14709  FTP°¡ Á¢¼ÓÀÌ ¾ÈµÅ´Âµ¥..      ÃÖÁ¾±Ô 2003/12/23 8979
14708    [re] ȨÆäÀÌÁö¸¦ º¸½Ã¸é...       2004/01/13 8973
14707  ftp»ç¿ë¿¡ °üÇÏ¿©....      ÃÖ⿬ 2004/02/02 8972
14706    [re] sql commander Áú¹®ÀÔ´Ï´Ù  [1]    ¹Ú±¤¼ö 2008/10/21 8966
14705  ¼­¹ö ÀÌÀü ¿äû  [1]    ±èÇüÅ 2009/06/29 8965
14704  È®ÀÎÇØ ÁÖ¼¼¿ä?  [1]    ±è±âÈñ 2019/04/24 8958
14703    [re] µð·º ¼ÒÀ¯±Ç º¯°æ½Åû      °¡°¡³ª¿ì 2004/03/28 8956
14702    [re] À̸ÞÀÏ¿¡ °üÇؼ­..       2003/12/28 8952
14701  2Â÷ DDOS °ø°Ý ¹ß»ý°ú ´ëÀÀ ¹× Á¶Ä¡»çÇ׿¡ ´ëÇÑ º¸°í       2007/02/09 8947
14700  ¸¶·çÄ«¿îÅÍ ºñÁî¹öÀü 1.0 ¹èÆ÷ ¾È³»       2007/11/22 8930
14699    [re] ¸ðµç À¥ÆÄÀÏÀÇ ¼³Ä¡°æ·Î´Â...       2003/12/20 8930
14698  ¸¶·ç´Ô °áÁ¦¿¡ ´ëÇؼ­ Áú¹®Àä..      ÀÓÀç»ê 2003/12/14 8929
14697  ¿øÇÁ·¹ÀÓ Áú¹®¿ä..±ÞÇؼ­...      À¯Àϳ² 2004/04/17 8924

 [1]..[21][22][23][24][25][26] 27 [28][29][30]..[593]