

| ¹øÈ£ | µî·ÏÀÏ | Á¦¸ñ | ||
|---|---|---|---|---|
| 40 | 2010.03.03 | [º¸¾È°øÁö] MS VBScript ¿ø°ÝÄÚµå ½ÇÇà Ãë¾àÁ¡À¸·Î ÀÎÇÑ Á¤º¸ °ø°³ |

1.¼³¸í
- ¿µÇâÀ» ¹Þ´Â Internet Explorer¸¦ »ç¿ëÇÒ ¶§ VBScript°¡ À©µµ¿ì µµ¿ò¸» ÆÄÀϰú »óÈ£ÀÛ¿ëÇÏ´Â Ãë¾àÁ¡ÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù. Ư¼öÇÏ°Ô Á¶ÀÛµÈ À¥ÆäÀÌÁö¿¡ ¹æ¹®½Ã ¸Þ½ÃÁö¹Ú½º¸¦ ¶ç¿ö »ç¿ëÀÚ°¡ F1۸¦ ´©¸£µµ·Ï À¯µµÇÏ¿© ¿ø°ÝÄڵ带 ½ÇÇàÇÒ ¼ö ÀÖ½À´Ï´Ù.
2. ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î
- Microsoft Internet Explorer 7.0.5730 .11
- Microsoft Internet Explorer 8 RC1
- Microsoft Internet Explorer 8
- Microsoft Internet Explorer 7.0
- Microsoft Internet Explorer 6.0 SP1
- Microsoft Internet Explorer 6.0
3. Àӽùæ¾È
- ÇöÀç ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ®´Â ¹ßÇ¥µÇÁö ¾Ê¾Ò±â ¶§¹®¿¡ ½Å·ÚÇÒ ¼ö ¾ø´Â »çÀÌÆ®¿¡´Â ¹æ¹®À» ÀÚÁ¦ÇØ¾ß ÇÕ´Ï´Ù.
- Internet Explorer »ç¿ë½Ã F1۸¦ ´©¸£Áö ¾Ê¾Æ¾ß ÇÕ´Ï´Ù.
- À©µµ¿ì µµ¿ò¸» ÆÄÀÏ¿¡ ´ëÇÑ Á¢±ÙÀ» Á¦ÇÑÇÕ´Ï´Ù.
¡Ø Ä¿¸Çµåâ¿¡¼ À©µµ¿ì µµ¿ò¸» ÆÄÀÏ¿¡ ´ëÇÑ Á¢±ÙÀ» Á¦ÇÑ/ÇØÁ¦ÇÏ´Â ¹æ¹ý
Á¦ÇÑ ¸í·É¾î : echo Y | cacls "%windir%\winhlp32.exe" /E /P everyone:N
ÇØÁ¦ ¸í·É¾î : echo Y | cacls "%windir%\winhlp32.exe" /E /R everyone
- º¸¾È ¾÷µ¥ÀÌÆ®°¡ ¹ßÇ¥µÇ±â Àü±îÁö JavaScript¸¦ »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÏ´Â ÀÓ½ÃÀûÀÎ ¹æ¾ÈÀÌ ÀÖ½À´Ï´Ù.
¡Ø JavaScript¸¦ »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤ÇÒ °æ¿ì »çÀÌÆ®°¡ Á¤»óÀûÀ¸·Î µ¿ÀÛÇÏÁö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù.
Internet Explorer > µµ±¸ > º¸¾È > ÀÎÅÍ³Ý > »ç¿ëÀÚ ÁöÁ¤ ¼öÁØ
"Active ½ºÅ©¸³ÆÃ"À» »ç¿ë ¾ÈÇÔÀ¸·Î ¼³Á¤
4. ÂüÁ¶ »çÀÌÆ® :
- ±¹¹® : http://www.boho.or.kr/index.jsp
- ¿µ¹® : http://www.microsoft.com/technet/security/advisory/981169.mspx
- ¿µ¹® : http://www.securityfocus.com/bid/38463/


