IIS¿¡¼­ Null È®Àå¸íÀ» Æ÷ÇÔÇÏ´Â ¿äûÀ» Çã¿ëÇϵµ·Ï URLScanÀ» ±¸¼ºÇÏ´Â ¹æ¹ý

±â¼ú ÀÚ·á: 312376 - ÀÌ ¹®¼­°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â.
ÀÌ ¹®¼­´Â ÀÌÀü¿¡ ´ÙÀ½ ID·Î ÃâÆÇµÇ¾úÀ½: KR312376
¸ðµç »ç¿ëÀÚ´Â Microsoft Windows Server 2003¿¡¼­ ½ÇÇàµÇ´Â Microsoft Internet Information Services(IIS) ¹öÀü 6.0À¸·Î ¾÷±×·¹À̵åÇÏ´Â °ÍÀÌ ÁÁ½À´Ï´Ù. IIS 6.0¿¡¼­´Â À¥ ÀÎÇÁ¶ó º¸¾ÈÀÌ »ó´çÈ÷ Çâ»óµÇ¾ú½À´Ï´Ù. IIS º¸¾È °ü·Ã Ç׸ñ¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇϽʽÿÀ.
http://www.microsoft.com/korea/technet/iis/default.asp
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

¿ä¾à

ÀÌ ¹®¼­¿¡¼­´Â ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º(IIS)¸¦ ÅëÇÑ Null È®Àå¸í ¿äûÀ» Çã¿ëÇϵµ·Ï URLScanÀ» ±¸¼ºÇÏ´Â ¹æ¹ýÀ» ´Ü°èº°·Î ¼³¸íÇÕ´Ï´Ù.

¼Ò°³

URLScanÀº IIS¿ë HTTP ¿äûÀ» °¡·Á³»¾î ¸ð´ÏÅ͸µÇÏ´Â ISAPI(ÀÎÅÍ³Ý ¼­¹ö ÀÀ¿ë ÇÁ·Î±×·¡¹Ö ÀÎÅÍÆäÀ̽º) ÇÊÅÍÀÔ´Ï´Ù. URLScanÀº ÀÎÅÍ³Ý °ø°ÝÀ¸·ÎºÎÅÍ IIS 4.0, IIS 5.0 ¹× IIS 5.1À» º¸È£ÇÏ´Â µ¥ »ç¿ëµË´Ï´Ù.

URLScanÀº ¼±ÅÃµÈ IIS ¼­ºñ½º ÀÀ¿ë ÇÁ·Î±×·¥¿¡ ´ëÇÑ HTTP ¿äûÀ» ÇÊÅ͸µÇÏ°í °ÅºÎÇÏ¿© °ø°ÝÀ¸·ÎºÎÅÍ À¥ ¼­¹ö¸¦ º¸È£ÇÕ´Ï´Ù. ±âº» Urlscan.ini ÆÄÀÏÀº ±×·¡ÇÈ ÆÄÀÏÀ» Æ÷ÇÔÇÏ´Â Á¤Àû HTML ÆÄÀϸ¸ ¹Þ¾ÆµéÀÌ°í ´ÙÀ½°ú °°Àº ¿äû À¯ÇüÀº °ÅºÎÇϵµ·Ï ±¸¼ºµÇ¾î ÀÖ½À´Ï´Ù.
  • CGI(Common Gateway Interface) .exe ÆäÀÌÁö
  • WebDAV(World Wide Web Distributed Authoring and Versioning)
  • FrontPage Server Extensions
  • Index Server
  • ÀÎÅÍ³Ý Àμâ
  • Server-side Include
URLScan ¹öÀü 6.0.3574.0ÀÌ ÀÖÀ¸¸é Null È®Àå¸íÀ» Æ÷ÇÔÇÏ´Â µé¾î¿À´Â URL ¿äûÀ» Çã¿ëÇϵµ·Ï URLScanÀ» ±¸¼ºÇÒ ¼ö ÀÖ½À´Ï´Ù.

±âº» URLScan ±¸¼º ¼öÁ¤

IIS À¥ ¼­¹ö¿¡ ¼³Ä¡µÉ ¶§ URLScanÀ» ±¸¼ºÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.
  1. ´ÙÀ½ Microsoft À¥ »çÀÌÆ®¿¡¼­ IIS Lockdown µµ±¸¸¦ ´Ù¿î·ÎµåÇÑ ÈÄ ·ÎÄà µð·ºÅ͸®¿¡ ÀúÀåÇÕ´Ï´Ù.
    http://www.microsoft.com/korea/technet/security/tools/locktool.asp
  2. IISlock.exe ÆÄÀÏÀÇ ¾ÐÃàÀ» Ç®°í Urlscan.exe ÆÄÀÏÀÇ ¾ÐÃàÀ» DZ´Ï´Ù. Urlscan Æú´õ°¡ ¸¸µé¾îÁý´Ï´Ù.
  3. %Windir%\System32\Inetsrv µð·ºÅ͸®¿¡ Urlscan Æú´õ¸¦ ºÙ¿©³Ö½À´Ï´Ù. lnetsrv ¾Æ·¡ÀÇ Urlscan Æú´õ¸¦ µÎ ¹ø ´©¸¥ ÈÄ ¸Þ¸ðÀå¿¡¼­ Urlscan.ini¸¦ ¿±´Ï´Ù.
  4. Urlscan.ini ÆÄÀÏ¿¡¼­ ´ÙÀ½°ú °°ÀÌ UseAllowExtensions¸¦ Ȱ¼ºÈ­ÇÕ´Ï´Ù.
    [Option]
    UseAllowExtensions=1; if 1, use [AllowExtensions] section, else
    					
  5. UrlscanÀ» »ç¿ëÇÏ¿© [AllowExtensions] ¼½¼Ç¿¡ Null È®Àå¸íÀ» ÁöÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ·¸°Ô ÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ [AllowExtensions] ¼½¼Ç¿¡ ¸¶Ä§Ç¥(.)¸¦ Ãß°¡ÇÕ´Ï´Ù.
    [AllowExtensions]
    .
    ;
    ; Extensions listed here are commonly used on a typical IIS server.
    ;
    ; Note that these entries are effective if "UseAllowExtensions=1"
    ; is set in the [Option] section above.
    ;
    .asp
    .htm
    .html
    .txt
    .jpg
    .jpeg
    .gif
    					
  6. ½ÃÀÛ ¸Þ´º¿¡¼­ ÇÁ·Î±×·¥À» °¡¸®Å°°í °ü¸® µµ±¸¸¦ °¡¸®Å² ÈÄ ÀÎÅÍ³Ý ¼­ºñ½º °ü¸®ÀÚ¸¦ ´©¸£°Å³ª IIS ½º³ÀÀÎÀÌ µé¾î ÀÖ´Â »ç¿ëÀÚ ÁöÁ¤ MMC(Microsoft Management Console)¸¦ ¿±´Ï´Ù.
  7. IIS MMC¿¡¼­ ¼­¹ö ÄÄÇ»ÅÍ À̸§À» È®ÀåÇÕ´Ï´Ù. ÇØ´ç ÄÄÇ»ÅÍ À̸§À» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃß·Î ´©¸¥ ÈÄ µî·Ï Á¤º¸¸¦ ´©¸¨´Ï´Ù. WWW ¼­ºñ½º¸¦ ´©¸¥ ÈÄ ÆíÁýÀ» ´©¸¨´Ï´Ù.
  8. ISAPI ÇÊÅÍ ÅÇ¿¡¼­ Ãß°¡¸¦ ´©¸¨´Ï´Ù. ÆÄÀÏ À̸§À¸·Î urlscanÀ» ÀÔ·ÂÇÕ´Ï´Ù. ½ÇÇà ÆÄÀÏ ÅØ½ºÆ® »óÀÚ¿¡¼­ ã¾Æº¸±â¸¦ ´©¸¥ ÈÄ %Windir%\System32\Inetsrv\Urlscan µð·ºÅ͸®¿¡¼­ urlscan.dllÀ» ¼±ÅÃÇÕ´Ï´Ù.
  9. MS-DOS ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼­ Net stop iisadminÀ» ½ÇÇàÇÑ ÈÄ Net start W3SVC¸¦ ½ÇÇàÇÏ¿© IIS À¥ ¼­ºñ½º¸¦ ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù. Urlscan.dllÀÌ ¹®Á¦ ¾øÀÌ ½ÇÇàµÇ´ÂÁö È®ÀÎÇÑ ÈÄ Urlscan.dll ISAPI ÇÊÅ͸¦ ÇÊÅÍ ¸ñ·ÏÀÇ ¸Ç À§·Î À̵¿ÇÕ´Ï´Ù.



ÂüÁ¶

URLSCAN À¯Æ¿¸®Æ¼ ¼³Ä¡ ¹× ±¸¼º ¹æ¹ý¿¡ ´ëÇÑ ÀÚ¼¼ÇÑ ³»¿ëÀº Microsoft ±â¼ú ÀÚ·áÀÇ ´ÙÀ½ ¹®¼­¸¦ ÂüÁ¶ÇϽʽÿÀ.
307608 IIS¿¡¼­ URLScan »ç¿ë









Microsoft Á¦Ç° °ü·Ã ±â¼ú Àü¹®°¡µé°ú ¿Â¶óÀÎÀ¸·Î Á¤º¸¸¦ ±³È¯ÇϽ÷Á¸é Microsoft ´º½º ±×·ì¿¡ Âü¿©ÇϽñ⠹ٶø´Ï´Ù.

¼Ó¼º

±â¼ú ÀÚ·á: 312376 - ¸¶Áö¸· °ËÅä: 2006³â 8¿ù 14ÀÏ ¿ù¿äÀÏ - ¼öÁ¤: 4.0
º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
  • Microsoft Internet Information Server 4.0
  • Microsoft Internet Information Services 5.0
  • Microsoft Internet Information Services 5.1
Ű¿öµå:?
kbhowto kbhowtomaster KB312376

Çǵå¹é º¸³»±â