[ °ø Áö ] Apache Struts2 ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡ ¾÷µ¥ÀÌÆ® ±Ç°í 2017-07-10

¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.

¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²²  Áø½ÉÀ¸·Î °¨»çµå¸®¸ç

Apache Struts2 ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡ ¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.

---------------------------------------------------------------------------

¡à °³¿ä
o Apache Struts¿¡¼­ ÀÓÀÇ ÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ Ãë¾àÁ¡ÀÌ ¹ß°ß [1]
  o Ãë¾àÇÑ ¹öÀüÀ» »ç¿ë ÁßÀÎ ¼­¹öÀÇ ´ã´çÀÚ´Â ¾Ç¼ºÄÚµå °¨¿° µîÀÇ À§ÇèÀÌ ÀÖÀ¸¹Ç·Î ¾Æ·¡ ÇØ°á ¹æ¾È¿¡ µû¸¥ Á¶Ä¡ ±Ç°í

  
¡à ³»¿ë
o Struts2¿¡¼­ Á¦°øÇÏ´Â À¥ ¾ÖÇø®ÄÉÀÌ¼Ç ShowcaseÀÇ SaveGangsterAction ÆäÀÌÁö¿¡¼­ ActionMessages.class¸¦ ÅëÇØ ƯÁ¤

    ÀÔ·Â °ªÀ» ó¸®ÇÒ ¶§ ¿ø°Ý ÄÚµå ½ÇÇàÀ» °¡´ÉÇÏ°Ô ÇÏ´Â Ãë¾àÁ¡(CVE-2017-9791)
  
  
¡à ¿µÇâÀ» ¹Þ´Â Á¦Ç° ¹× ¹öÀü
o Apache Struts 2.3.x ¹öÀü¿¡¼­ Struts1 Ç÷¯±×ÀÎÀ» »ç¿ëÇÏ´Â °æ¿ì
   ¡Ø Apache Struts2´Â Struts 1ÀÇ ActionÀ» »ç¿ëÇϱâ À§ÇØ Struts1 Ç÷¯±×ÀÎ ±âº» Á¦°ø

  
¡à ÇØ°á ¹æ¾È
o Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹ÞÁö ¾Ê´Â ¹öÀüÀ¸·Î ¾÷µ¥ÀÌÆ® ¼öÇà
   - Apache Struts 2.5.10.1 ¹öÀü [2]
  o SaveGangsterAction.java¿¡¼­ ActionMessage.class¿¡ ¸Þ½ÃÁö¸¦ Àü´ÞÇÒ ¶§ °ªÀ» Á÷Á¢ Àü´ÞÇÏ´Â ´ë½Å ¸®¼Ò½º ۸¦ »ç¿ëÇϵµ·Ï

    ¼Ò½ºÄÚµå º¯°æ ÈÄ ÄÄÆÄÀÏ
     ¡Ø SaveGangsterAction.java ÆÄÀÏ °æ·Î : showcase°¡ ¼³Ä¡µÈ Æú´õ ÇÏÀ§ÀÇ \src\org\apache\struts2\integration

         \SaveGangsterAction.java (¼³Ä¡ ȯ°æ¿¡ µû¶ó °æ·Î È®ÀÎ ÇÊ¿ä)



±âÁ¸ ¼Ò½º ÄÚµå messages.add("msg", new ActionMessage("Gangster " + gform.getName() + " was added"));
º¯°æ ¼Ò½º ÄÚµå messages.add("msg", new ActionMessage("struts1.gangsterAdded", gform.getName()));

  o º¸¾È±ÔÄ¢(2Á¾) : ¿ìȸ Ãë¾à°æ·Î(/struts2-showcase/integration/saveGangster.action)¿¡ ´ëÇÑ Ãß°¡ Â÷´Ü
    ¡Ø º¸¾È±ÔÄ¢Àº °¢ ±â°ü ȯ°æ¿¡ ¸ÂÃç °ËÅä ÈÄ Àû¿ë ÇÊ¿ä
alert tcp any any -> any any (content:"/saveGangster.action"; nocase; content:"HTTP/1."; distance:0;)
alert tcp any any -> any any (content:"/struts2-showcase"; nocase; content:"HTTP/1."; distance:0;)



¡à ±âŸ ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
  
[Âü°í»çÀÌÆ®]
  [1] https://cwiki.apache.org/confluence/display/WW/S2-048
  [2] https://cwiki.apache.org/confluence/display/WW/Version+Notes+2.5.10.1

---------------------------------------------------------------------------

                    Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼­ºñ½º  [ È£½ºÆ®¸ÕÆ® ]