Java´Â ´ÙÀ½ µÎ °¡Áö ¹æ¹ýÀ¸·Î È£ÃâÇÒ ¼ö ÀÖÀ¸¹Ç·Î µ¶Æ¯ÇÑ ÇüÅÂÀÇ È®Àå ÇÁ·Î±×·¥À̶ó°í ÇÒ ¼ö ÀÖ½À´Ï´Ù.
- ¾ÖÇø´
(http://msdn.microsoft.com/ko-kr/library/ms535183(v=vs.85).aspx)
¿ä¼Ò »ç¿ë - JVM(Java Virtual Machine)ÀÇ CLSID¸¦ °®´Â °³Ã¼
(http://msdn.microsoft.com/ko-kr/library/ms535859(v=vs.85).aspx)
¿ä¼Ò »ç¿ë
ÀÌ·¯ÇÑ µÎ °¡Áö È£Ãâ ¹æ¹ý¿¡´Â ´Ù¸¥ º¸¾È ÄÁÆ®·ÑÀÌ Àû¿ëµË´Ï´Ù. ÀÌ ±â¼ú ÀÚ·á ¹®¼¿¡´Â ·¹Áö½ºÆ®¸®¸¦ ÅëÇØ ÀÌ·¯ÇÑ µÎ º¸¾È ÄÁÆ®·ÑÀ» ±¸¼ºÇϱâ À§ÇÑ ÁöħÀÌ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.?
?°í°´Àº Java CLSID¿ë kill ºñÆ®¸¦ ¼³Á¤Çϰųª URL µ¿ÀÛÀ»
Disable·Î ¼³Á¤ÇÏ¿© Java¸¦ »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.
Áß¿ä ÀÌ Àý, ¹æ¹ý ¶Ç´Â ÀÛ¾÷¿¡´Â ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤ÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ´Ü°è°¡ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù. ±×·¯³ª ·¹Áö½ºÆ®¸®¸¦ À߸ø ¼öÁ¤ÇÏ¸é ½É°¢ÇÑ ¹®Á¦°¡ ¹ß»ýÇÒ ¼öµµ ÀÖÀ¸¹Ç·Î ´ÙÀ½ ´Ü°è¸¦ ÁÖÀÇÇÏ¿© ¼öÇàÇØ¾ß ÇÕ´Ï´Ù. Ãß°¡ º¸È£ Á¶Ä¡·Î ·¹Áö½ºÆ®¸®¸¦ ¼öÁ¤Çϱâ Àü¿¡ ÇØ´ç ·¹Áö½ºÆ®¸®¸¦ ¹é¾÷ÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ¸é ¹®Á¦°¡ ¹ß»ýÇÏ´Â °æ¿ì ·¹Áö½ºÆ®¸®¸¦ º¹¿øÇÒ ¼ö ÀÖ½À´Ï´Ù. ·¹Áö½ºÆ®¸® ¹é¾÷ ¹× º¹¿ø ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ ¹®¼ ¹øÈ£¸¦ Ŭ¸¯ÇÏ¿© Microsoft ±â¼ú ÀÚ·á ¹®¼¸¦ ÂüÁ¶ÇϽʽÿÀ.
322756
(http://support.microsoft.com/kb/322756/ko/
)
Windows XP ¹× Windows Server 2003¿¡¼ ·¹Áö½ºÆ®¸®¸¦ ¹é¾÷, ÆíÁý ¹× º¹¿øÇÏ´Â ¹æ¹ý
{8AD9C840-044E-11D1-B3E9-00805F499D93}, {CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0001-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0002-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0003-FFFF-ABCDEFFEDCBA}, CAFEEFAC-0017-0004-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0004-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0005-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-0017-0006-FFFF-ABCDEFFEDCBA}, {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} °ªÀ» °®´Â CLSID¿¡ ´ëÇØ kill ºñÆ®¸¦ ¼³Á¤ÇÏ·Á¸é ¸Þ¸ðÀå°ú °°Àº ÅØ½ºÆ® ÆíÁý±â¸¦ »ç¿ëÇÏ¿© ´ÙÀ½ ÅØ½ºÆ®¸¦ ÅØ½ºÆ® ÆÄÀÏ¿¡ ºÙ¿© ³ÖÀ¸½Ê½Ã¿À. ±×·± ÈÄ .reg ÆÄÀÏ À̸§ È®Àå¸íÀ» »ç¿ëÇÏ¿© ÆÄÀÏÀ» ÀúÀåÇÕ´Ï´Ù.
Windows Registry Editor Version 5.00
; First set the URLAction to control APPLET behavior
; Zone 3 is the Internet zone
; 1C00 is the Java invocation policy
; dword:00000000 sets the policy to disable
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1C00"=dword:00000000
; Then set the Internet Explorer kill bit to block OBJECT tag invocation
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{8AD9C840-044E-11D1-B3E9-00805F499D93}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0000-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0001-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0001-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0002-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0002-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0003-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0003-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0004-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0004-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0005-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0005-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0006-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-0017-0006-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Internet Explorer\ActiveX Compatibility\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}]
"Compatibility Flags"=dword:00000400
ÀÌ .reg ÆÄÀÏÀ» µÎ ¹ø Ŭ¸¯ÇÏ¿© °³º° ½Ã½ºÅÛ¿¡ Àû¿ëÇÕ´Ï´Ù. ±×·ì Á¤Ã¥À» »ç¿ëÇÏ¿© ¿©·¯ µµ¸ÞÀο¡ Àû¿ëÇÒ ¼öµµ ÀÖ½À´Ï´Ù. ±×·ì Á¤Ã¥¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ TechNet ¹®¼¸¦ ÂüÁ¶ÇϽʽÿÀ.
±×·ì Á¤Ã¥ Ä÷º¼Ç
(http://technet.microsoft.com/ko-kr/library/cc784165(WS.10).aspx)
Âü°í º¯°æ ³»¿ëÀ» Àû¿ëÇÏ·Á¸é Internet Explorer¸¦ ´Ù½Ã ½ÃÀÛÇØ¾ß ÇÕ´Ï´Ù.
º¯°æ ³»¿ëÀ» ½ÇÇà Ãë¼ÒÇÏ´Â ¹æ¹ý
ÀÌ º¯°æ ³»¿ëÀ» ±¸ÇöÇÒ ¶§ Ãß°¡µÈ ·¹Áö½ºÆ®¸® Ç׸ñÀ» »èÁ¦ÇϽʽÿÀ.
Kill ºñÆ®¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº
Microsoft ±â¼ú ÀÚ·á ¹®¼ 240797
(http://support.microsoft.com/kb/240797/ko)
: ActiveX ÄÁÆ®·ÑÀÌ Internet Explorer¿¡¼ ½ÇÇàµÇÁö ¾Êµµ·Ï ÇÏ´Â ¹æ¹ýÀ» ÂüÁ¶ÇϽʽÿÀ.
Internet Explorer URL µ¿ÀÛ¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft TechNet ¹®¼
Internet Explorer URL µ¿ÀÛ ¹× ±×·ì Á¤Ã¥ÀÇ °í±Þ º¸¾È ¼³Á¤
(http://technet.microsoft.com/ko-kr/library/cc783259(v=WS.10).aspx)
À» ÂüÁ¶ÇϽʽÿÀ.
Âü°í À̰ÍÀº Microsoft ±â¼ú Áö¿ø ¼ºñ½º ³»¿¡¼ Á÷Á¢ ÀÛ¼ºÇÑ ¡°ºü¸¥ °Ô½Ã¡± ¹®¼ÀÔ´Ï´Ù. ¿©±â¿¡ Æ÷ÇÔµÈ Á¤º¸´Â ¹ß»ýÇÑ ¹®Á¦¿¡ ´ëÇØ ÀÖ´Â ±×´ë·Î Á¦°øµË´Ï´Ù. ÀÌ ¹®¼´Â Áï½Ã ÂüÁ¶ÇÒ ¼ö ÀÖµµ·Ï ºü¸£°Ô ÀÛ¼ºµÇ¾î¼ Ç¥±â»óÀÇ ¿À·ù°¡ Æ÷ÇԵǾî ÀÖÀ» ¼ö ÀÖ°í ¾ðÁ¦µçÁö ¿¹°í ¾øÀÌ ¼öÁ¤µÉ ¼ö ÀÖ½À´Ï´Ù. ±âŸ °í·Á »çÇ×Àº
»ç¿ë ¾à°ü
(http://go.microsoft.com/fwlink/?LinkId=151500)
À» ÂüÁ¶ÇϽʽÿÀ.
Á¤º¸
±â¼ú ÀÚ·á: 2751647 - ¸¶Áö¸· °ËÅä: 2012³â 8¿ù 31ÀÏ ±Ý¿äÀÏ - ¼öÁ¤: 1.0
º» ¹®¼ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
- Windows Internet Explorer 9?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Windows Server 2008 R2 Datacenter
- Windows Server 2008 R2 Enterprise
- Windows Server 2008 R2 Standard
- Windows Web Server 2008 R2
- Windows 7 Enterprise
- Windows 7 Home Basic
- Windows 7 Home Premium
- Windows 7 Professional
- Windows 7 Ultimate
- Windows Server 2008 for Itanium-Based Systems
- Windows Server 2008 Datacenter
- Windows Server 2008 Enterprise
- Windows Server 2008 Standard
- Windows Web Server 2008
- Windows Vista Business
- Windows Vista Enterprise
- Windows Vista Home Basic
- Windows Vista Home Premium
- Windows Vista Ultimate
- Windows Vista Enterprise 64-bit edition
- Windows Vista Home Basic 64-bit edition
- Windows Vista Home Premium 64-bit edition
- Windows Vista Ultimate 64-bit edition
- Windows Vista Business 64-bit edition
- Windows Internet Explorer 8?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Windows Server 2008 R2 Datacenter
- Windows Server 2008 R2 Enterprise
- Windows Server 2008 R2 Standard
- Windows Web Server 2008 R2
- Windows 7 Enterprise
- Windows 7 Home Basic
- Windows 7 Home Premium
- Windows 7 Professional
- Windows 7 Ultimate
- Windows Server 2008 for Itanium-Based Systems
- Windows Server 2008 Datacenter
- Windows Server 2008 Enterprise
- Windows Server 2008 Standard
- Windows Web Server 2008
- Windows Vista Business
- Windows Vista Enterprise
- Windows Vista Home Basic
- Windows Vista Home Premium
- Windows Vista Ultimate
- Windows Vista Enterprise 64-bit edition
- Windows Vista Home Basic 64-bit edition
- Windows Vista Home Premium 64-bit edition
- Windows Vista Ultimate 64-bit edition
- Windows Vista Business 64-bit edition
- Microsoft Windows XP Professional
- Microsoft Windows XP Home Edition
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003, Datacenter x64 Edition
- Microsoft Windows Server 2003, Enterprise x64 Edition
- Microsoft Windows Server 2003, Standard x64 Edition
- Microsoft Windows Server 2003, Web Edition
- Microsoft Windows Server 2003, Standard Edition (32-bit x86)
- Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
- Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
- Windows Internet Explorer 7?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Windows Server 2008 for Itanium-Based Systems
- Windows Server 2008 Datacenter
- Windows Server 2008 Enterprise
- Windows Server 2008 Standard
- Windows Web Server 2008
- Windows Vista Business
- Windows Vista Enterprise
- Windows Vista Home Basic
- Windows Vista Home Premium
- Windows Vista Ultimate
- Windows Vista Enterprise 64-bit edition
- Windows Vista Home Basic 64-bit edition
- Windows Vista Home Premium 64-bit edition
- Windows Vista Ultimate 64-bit edition
- Windows Vista Business 64-bit edition
- Microsoft Windows XP Professional
- Microsoft Windows XP Home Edition
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003, Datacenter x64 Edition
- Microsoft Windows Server 2003, Enterprise x64 Edition
- Microsoft Windows Server 2003, Standard x64 Edition
- Microsoft Windows Server 2003, Web Edition
- Microsoft Windows Server 2003, Standard Edition (32-bit x86)
- Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
- Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
- Microsoft Internet Explorer 6.0?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
- Microsoft Windows XP Professional
- Microsoft Windows XP Home Edition
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003, Datacenter x64 Edition
- Microsoft Windows Server 2003, Enterprise x64 Edition
- Microsoft Windows Server 2003, Standard x64 Edition
- Microsoft Windows Server 2003, Web Edition
- Microsoft Windows Server 2003, Standard Edition (32-bit x86)
- Microsoft Windows Server 2003, Enterprise Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
- Microsoft Windows Server 2003, Datacenter Edition for Itanium-Based Systems
- Microsoft Windows Server 2003, Enterprise Edition for Itanium-based Systems
| kbexpertiseinter kbsecurity KB2751647 |