BUG: MS03-032 º¸¾È ¾÷µ¥ÀÌÆ®¸¦ ¼³Ä¡ÇÑ ÈÄ ASP.NET¿¡¼­ "¼­¹ö ÀÀ¿ë ÇÁ·Î±×·¥ ¾øÀ½" ¿À·ù ¸Þ½ÃÁö

±â¼ú ÀÚ·á: 827641 - ÀÌ ¹®¼­°¡ Àû¿ëµÇ´Â Á¦Ç° º¸±â.
¸ðµÎ È®´ë | ¸ðµÎ Ãà¼Ò

ÀÌ ÆäÀÌÁö¿¡¼­

Çö»ó

Microsoft ASP.NET 1.0À» ¼³Ä¡ÇÑ Microsoft Windows XP¸¦ ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ¿¡ ÆÐÄ¡¸¦ Àû¿ëÇÒ ¶§ Microsoft´Â ÃÖ±Ù MS03-32 º¸¾È ¾÷µ¥ÀÌÆ®¿¡ ´ëÇÑ Internet Explorer º¸¾È ÆÐÄ¡ÀÇ ¹ö±×¸¦ È®ÀÎÇß½À´Ï´Ù. ¼öµ¿À¸·Î ¶Ç´Â Windows Update À¥ »çÀÌÆ®¿¡¼­ ÃֽŠÁß¿ä ¾÷µ¥ÀÌÆ®¸¦ ¾ò´Â ÀÌ ÆÐÄ¡¸¦ ¼³Ä¡ÇÒ ¼ö ÀÖ½À´Ï´Ù.

ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ ÈÄ ASP.NET ¿äûÀÌ ÀÖÀ» ¶§ ´ÙÀ½ ¿À·ù ¸Þ½ÃÁö°¡ ³ªÅ¸³³´Ï´Ù.
¼­¹ö ÀÀ¿ë ÇÁ·Î±×·¥À» »ç¿ëÇÒ ¼ö ¾ø½À´Ï´Ù
ÀÌ ¹ö±×´Â ASP.NET 1.0À» Windows XP¸¦ ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ¿¡¸¸À» ¿µÇâÀ» ÁÝ´Ï´Ù. Microsoft Windows 2000 ¶Ç´Â Microsoft Windows Server 2003À» ½ÇÇà ÁßÀÎ ÄÄÇ»ÅÍ¿¡´Â ¿µÇâÀ» ÁÖÁö ¾Ê½À´Ï´Ù. ÀÌ ¹ö±×´Â ¶ÇÇÑ Windows¸¦ ½ÇÇàÇÏ´Â ÄÄÇ»ÅÍ¿¡´Â ¿µÇâÀ» ÁÖÁö ¾Ê½À´Ï´Ù XP¿Í ÀÖ´Â ASP.NET 1.1À» ¼³Ä¡ÇÑ.

´ÙÀ½ Ç¥¿¡¼­´Â ¿î¿µ üÁ¦¿Í ÀÌ ¹ö±×ÀÇ ¿µÇâÀ» ¹Þ´Â Microsoft .NET Framework ¹öÀüÀ» º¸¿© ÁÝ´Ï´Ù.
Ç¥ Ãà¼ÒÇ¥ È®´ë
.NET Framework ¹öÀü¿î¿µ üÁ¦¿µÇâÀ» ¹Þ´Â
1.0Windows 2000 Professional¾Æ´Ï¿À
1.0Windows 2000 Server¾Æ´Ï¿À
1.0Windows XP Professional¿¹
1.0Windows Server 2003¾Æ´Ï¿À
1.1Windows 2000 Professional¾Æ´Ï¿À
1.1Windows 2000 Server¾Æ´Ï¿À
1.1Windows XP Professional¾Æ´Ï¿À
1.1Windows Server 2003¾Æ´Ï¿À

ÇØ°á °úÁ¤

ÀÌ ¹ö±×¸¦ ÇØ°áÇÏ·Á¸é ÀÌ ¹®¼­ÀÇ "¹èÄ¡ ÆÄÀÏ" Àý¿¡¼­ ¼³¸íÇÏ´Â ¹èÄ¡ ÆÄÀÏÀ» ½ÇÇàÇϽʽÿÀ. ÀÌ ¹èÄ¡ ÆÄÀÏ¿¡ ´ÙÀ½ ÀÛ¾÷À» ¼öÇàÇÕ´Ï´Ù.
  1. IIS ¹× ASP.NET »óÅ ¼­ºñ½º¸¦ ÁßÁöÇÕ´Ï´Ù.
  2. »èÁ¦ÇÏ°í ¾Ë·ÁÁøµÈ Àӽà ¾ÏÈ£¸¦ »ç¿ëÇÏ¿© ASPNET °èÁ¤À» ´Ù½Ã ¸¸µì´Ï´Ù.
  3. Windows runas ¸í·ÉÀ» »ç¿ëÇÏ¿© ASPNET »ç¿ëÀÚ ÇÁ·ÎÇÊÀ» ¸¸µç ½ÇÇà ÆÄÀÏÀ» ½ÃÀÛÇÕ´Ï´Ù. ÀÌ ¹®Á¦¸¦ ÇØ°áÇÏ·Á¸é ASPNET »ç¿ëÀÚ ÇÁ·ÎÇÊÀ» »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.
  4. ASP.NET reregisters. ÀÌ ´Ü°è´Â °èÁ¤¿¡ ´ëÇÑ »õ ÀÓÀÇ ¾ÏÈ£¸¦ ¸¸µé°í °èÁ¤¿¡ ´ëÇÑ ±âº» ASP.NET ¾×¼¼½º Á¦¾î ¼³Á¤À» Àû¿ëÇÕ´Ï´Ù.
  5. Microsoft ÀÎÅÍ³Ý Á¤º¸ ¼­ºñ½º (IIS) ´Ù½Ã ¼­ºñ½º.
¹èÄ¡ ÆÄÀÏ "1pass@word" ÀÇ Àӽà Çϵå ÄÚµåµÈ ¾ÏÈ£¸¦ Æ÷ÇÔÇÕ´Ï´Ù. runas ¸í·ÉÀ» ¹èÄ¡ ÆÄÀÏÀ» ½ÇÇàÇÒ ¶§ ÀÌ ¾ÏÈ£¸¦ ÀÔ·ÂÇϵµ·Ï ¹¯½À´Ï´Ù. runas ¸í·ÉÀÌ ¿Ï·áµÈ ÈÄ ASPNET °èÁ¤ ¾ÏÈ£°¡ °­·ÂÇÑ ÀÓÀÇÀÇ °ªÀ» »ç¿ëÇÏ¿© ´Ù½Ã ¸¸µé¾îÁý´Ï´Ù.

Áß¿äÇÑ Á¤º¸

  • ¹èÄ¡ ÆÄÀÏÀ» Çϵå ÄÚµåµÈ ¾ÏÈ£¸¦ »ç¿ëÀÚ È¯°æÀÇ ¾ÏÈ£ º¹À⼺ ¿ä±¸ »çÇ×À» ÃæÁ·ÇÏ´Â °æ¿ì ½ÇÆÐÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ ¹®Á¦°¡ ¹ß»ýÇÏ¸é »ç¿ëÀÚ È¯°æ¿¡ ÀûÇÕÇÑ ´Ù¸¥ °ªÀ» ¾ÏÈ£¸¦ º¯°æÇÒ ¼ö ÀÖ½À´Ï´Ù.
  • »ç¿ëÀÚ ÁöÁ¤ ¾×¼¼½º Á¦¾î ¼³Á¤À» ¶Ç´Â µ¥ÀÌÅͺ£À̽º °èÁ¤ ±ÇÇÑÀ» ASPNET °èÁ¤¿¡ ´ëÇØ Ãß°¡ÇÑ °æ¿ì ÀÌ ¹èÄ¡ ÆÄÀÏÀÌ ¿Ï·áµÈ ÈÄ ÀÌ·¯ÇÑ ¼³Á¤ ¶Ç´Â »ç¿ë ±ÇÇÑÀ» ¸¸µé¾î¾ß ÇÕ´Ï´Ù. °èÁ¤À» ´Ù½Ã ¸¸µé ¶§ »õ º¸¾È ½Äº°ÀÚ (SID)ÀÌ ÀÌ °èÁ¤¿¡ ÇÒ´çµÈ ¶§¹®ÀÔ´Ï´Ù.
  • ASPNET °èÁ¤¿¡¼­ ´Ù¸¥ »ç¿ëÀÚ ÁöÁ¤ °èÁ¤À» »ç¿ëÇÏ¿© ASP.NET ÀÛ¾÷ÀÚ ÇÁ·Î¼¼½º¸¦ ½ÇÇàÇÏ´Â °æ¿ì ÀÌ ¹èÄ¡ ÆÄÀÏÀ» ½ÇÇàÇÏÁö ¸¶½Ê½Ã¿À. ´ë½Å, »ç¿ëÀÚ°¡ ÄÄÇ»ÅÍ¿¡ ´ëÈ­ÇüÀ¸·Î ·Î±×¿ÂÇØ¾ß ¶Ç´Â runas ¸í·ÉÀ» »ç¿ëÇÏ¿© ÇØ´ç »ç¿ëÀÚ ÁöÁ¤ °èÁ¤À» »ç¿ëÇØ¾ß ÇÕ´Ï´Ù. ÀÌ ÀýÂ÷¿¡¼­´Â »ç¿ëÀÚ ÁöÁ¤ °èÁ¤¿¡ ´ëÇÑ »ç¿ëÀÚ ÇÁ·ÎÇÊÀ» ¸¸µì´Ï´Ù.
¹èÄ¡ ÆÄÀÏÀ» »ç¿ëÇÏ·Á¸é ´ÙÀ½°ú °°ÀÌ ÇϽʽÿÀ.

Âü°í »ç¿ëÀÚ °èÁ¤À» Administrators ±×·ìÀÇ ±¸¼º¿øÀ̾î¾ß ÇÕ´Ï´Ù.
  1. ¸Þ¸ðÀåÀ» ½ÇÇàÇÕ´Ï´Ù. ÁÙ ¹Ù²Þ ÇØÁ¦µÇ¾î ÀÖ´ÂÁö È®ÀÎÇϽʽÿÀ.
  2. ¹èÄ¡ ÆÄÀÏ Äڵ带 ¸Þ¸ðÀå¿¡ ºÙ¿© ³Ö½À´Ï´Ù.
  3. ·Î c:\fixup.cmd ÆÄÀÏÀ» ÀúÀåÇϽʽÿÀ.
  4. ½ÃÀÛ À» ´©¸¥ ´ÙÀ½ ½ÇÇà À» Ŭ¸¯ÇϽʽÿÀ.
  5. cmd.exe ¸¦ ÀÔ·ÂÇÑ ´ÙÀ½ Enter ۸¦ ´©¸¨´Ï´Ù.
  6. ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼­ c:\fixup.cmd ¸¦ ÀÔ·ÂÇÑ ´ÙÀ½ Enter ۸¦ ´©¸¨´Ï´Ù.
  7. ¾ÏÈ£¸¦ ¹¯´Â ¸Þ½ÃÁö°¡ ³ªÅ¸³ª¸é 1pass@word¸¦ ÀÔ·ÂÇϽʽÿÀ.

    µÎ ¹øÂ° ¸í·É ÇÁ·ÒÇÁÆ® âÀÌ ³ªÅ¸³³´Ï´Ù.
  8. ÆÐÄ¡¸¦ Àû¿ëÇÑ ÈÄ ³¡³»·Á¸é µÎ ¹øÂ° ¸í·É ÇÁ·ÒÇÁÆ® â¿¡¼­ ÀÔ·ÂÇÑ ´ÙÀ½ Enter ۸¦ ´©¸¨´Ï´Ù.
  9. ÀÌÁ¦ »ç¿ëÀÚ ÁöÁ¤ ¾×¼¼½º Á¦¾î ¼³Á¤À» ¶Ç´Â µ¥ÀÌÅͺ£À̽º °èÁ¤ ±ÇÇÑÀ» ASPNET °èÁ¤¿¡ ´ëÇØ ÀÌÀü¿¡ ±¸¼ºÇÑ °æ¿ì ÀÌ·¯ÇÑ ¼³Á¤À» ´Ù½Ã Àû¿ëÇØ¾ß ÇÕ´Ï´Ù.

¹èÄ¡ ÆÄÀÏ

REM Start Batch File
REM This batch file addresses issues that exist with the MS03-32 
REM Security Update when you run ASP.NET 1.0 on Windows XP.
REM If you have any other configuration, do not run this file.
@echo off 

if exist %SystemRoot%\microsoft.net\framework\v1.1* goto v11_installed

REM Change to the .NET Framework installation directory.
cd /d %SystemRoot%\microsoft.net\framework\v1.0.3705 

echo "Stopping IIS."
iisreset /stop 
echo "----------------------"

echo "Stopping the ASP.NET state service if it is running."
net stop aspnet_state
echo "----------------------"

echo "Deleting the ASPNET account."
net user ASPNET /delete 
echo "----------------------"

echo "Creating a new ASPNET account with a temporary password."
net user ASPNET 1pass@word /add 
echo "----------------------"

echo "Launching runas to create a profile."
echo "You see a command window being created."
echo "Type 1pass@word when you are prompted for the temporary password." 
runas /profile /user:ASPNET cmd.exe 
echo "----------------------"

echo "Reregistering ASP.NET and the ASPNET account."
aspnet_regiis -i 
echo "A new random password has been autocreated for the ASPNET account."
echo "----------------------"

echo "Restarting IIS."
iisreset /start 
echo "----------------------"

echo "The workaround has been applied."
echo "Try to access an ASP.NET page."
echo "If you have any custom access controls settings for the ASPNET account,"
echo "you must re-create them."
echo "If you were running the ASP.NET state service, you must restart it."
goto done

:v11_installed
echo "Version 1.1 appears to be installed. Do not run this file."

:done
REM End of batch file.

ÇöÀç »óÅÂ

Microsoft´Â ÀÌ ¹®¼­ÀÇ ½ÃÀÛ ºÎºÐ¿¡ ³ª¿­ÇÑ Á¦Ç°¿¡¼­ ¹®Á¦¸¦ È®ÀÎÇß½À´Ï´Ù.

¼Ó¼º

±â¼ú ÀÚ·á: 827641 - ¸¶Áö¸· °ËÅä: 2004³â 1¿ù 21ÀÏ ¼ö¿äÀÏ - ¼öÁ¤: 3.3
º» ¹®¼­ÀÇ Á¤º¸´Â ´ÙÀ½ÀÇ Á¦Ç°¿¡ Àû¿ëµË´Ï´Ù.
  • Microsoft ASP.NET 1.0?À»(¸¦) ´ÙÀ½°ú ÇÔ²² »ç¿ëÇßÀ» ¶§
    • the operating system: Microsoft Windows XP
Ű¿öµå:?
kbmt kbbug KB827641 KbMtko
±â°è ¹ø¿ªµÈ ¹®¼­
Áß¿ä: º» ¹®¼­´Â Àü¹® ¹ø¿ª°¡°¡ ¹ø¿ªÇÑ °ÍÀÌ ¾Æ´Ï¶ó Microsoft ±â°è ¹ø¿ª ¼ÒÇÁÆ®¿þ¾î·Î ¹ø¿ªÇÑ °ÍÀÔ´Ï´Ù. Microsoft´Â ¹ø¿ª°¡°¡ ¹ø¿ªÇÑ ¹®¼­ ¹× ±â°è ¹ø¿ªµÈ ¹®¼­¸¦ ¸ðµÎ Á¦°øÇϹǷΠMicrosoft ±â¼ú ÀÚ·á¿¡ ÀÖ´Â ¸ðµç ¹®¼­¸¦ Çѱ۷ΠÁ¢ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¯³ª ±â°è ¹ø¿ª ¹®¼­°¡ Ç×»ó ¿Ïº®ÇÑ °ÍÀº ¾Æ´Õ´Ï´Ù. µû¶ó¼­ ±â°è ¹ø¿ª ¹®¼­¿¡´Â ¸¶Ä¡ ¿Ü±¹ÀÎÀÌ Çѱ¹¾î·Î ¸»ÇÒ ¶§ ½Ç¼ö¸¦ ÇÏ´Â °Íó·³ ¾îÈÖ, ±¸¹® ¶Ç´Â ¹®¹ý¿¡ ¿À·ù°¡ ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù. Microsoft´Â ³»¿ë»óÀÇ ¿À¿ª ¶Ç´Â Microsoft °í°´ÀÌ ÀÌ·¯ÇÑ ¿À¿ªÀ» »ç¿ëÇÔÀ¸·Î½á ¹ß»ýÇÏ´Â ºÎ Á¤È®¼º, ¿À·ù ¶Ç´Â ¼ÕÇØ¿¡ ´ëÇØ Ã¥ÀÓÀ» ÁöÁö ¾Ê½À´Ï´Ù. Microsoft´Â ÀÌ·¯ÇÑ ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇØ ±â°è ¹ø¿ª ¼ÒÇÁÆ®¿þ¾î¸¦ ÀÚÁÖ ¾÷µ¥ÀÌÆ®Çϰí ÀÖ½À´Ï´Ù.

Çǵå¹é º¸³»±â