83, 1/5 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   sjh21a
   http://kernelhack.co.kr
   [Á¤º¸] MS Internet Explorer XML Parsing Remote Buffer overflow zer0-day

http://www.hackerschool.org/HS_Boards/zboard.php?id=HS_Notice&no=1170881860 [º¹»ç]


MS ÀÇ ÀÎÅÍ³Ý ÀͽºÇ÷η¯ 7.0 ¹öÀü¿¡¼­ XML Çڵ鸵 ½Ã,

¿ø°ÝÀ¸·Î °ø°Ý Äڵ带 ½ÇÇà ½Ãų ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ ¹ß°ß µÇ¾ú½À´Ï´Ù.

°ø°ÝÀÚ´Â °ø°Ý ¼º°ø½Ã ÇØ´ç ½Ã½ºÅÛ¿¡ ¿øÇÏ´Â °ø°Ý Äڵ带 ½ÇÇà ½Ãų ¼ö ÀÖ½À´Ï´Ù.

ÀÓ½ÃÀûÀÎ ÆÐÄ¡·Î´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ´Â oledb32.dll ÆÄÀÏÀ» ºñÈ°¼º ½ÃÅ°´Â °É·Î ÇØ°á ÇÒ ¼ö ÀÖ½À´Ï´Ù.

ÀÚ½ÅÀÇ PC°¡ À§ Ãë¾àÁ¡¿¡ °ø°Ý ´çÇÒ °¡´É¼ºÀÌ ÀÖ´ÂÁö, ¾Æ´ÑÁö ÆÇ´Ü Çغ¸½Ã·Á¸é

¾Æ·¡ÀÇ URL ·Î Á¢¼ÓÇØ º¸½Ã¸é µË´Ï´Ù.

http://research.hackerschool.org/JUST_TESTS/xml.html

Á¢¼Ó½Ã, ¿¡·¯ ¸Þ½ÃÁö¿Í IE°¡ Á¾·á µÇ¸é Ãë¾àÇÑ »óÅ ÀÔ´Ï´Ù.

¾Æ·¡ÀÇ Àӽà ÆÐÄ¡¸¦ ÇØÁֽøé, Á¾·á°¡ µÇÁö ¾Ê½À´Ï´Ù.

"½ÃÀÛ -> ½ÇÇà" ÈÄ ¾Æ·¡ ³»¿ë ÀÔ·Â.

Regsvr32.exe /u "%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll"


Â÷ÈÄ¿¡ MS Ãø¿¡¼­ ÆÐÄ¡°¡ ³ª¿À¸é ¾Æ·¡ÀÇ ¸í·ÉÀ¸·Î oledb32.dll À» ´Ù½Ã µî·Ï ½ÃÄÑ ÁÖ½Ã¸é µË´Ï´Ù.

Regsvr32.exe "%ProgramFiles%\Common Files\System\Ole DB\oledb32.dll"


Âü°í¹®¼­

http://www.securityfocus.com/bid/32721

  Hit : 9104     Date : 2008/12/17 05:01



    
wadeco ¾È²¨Áö°í ¿¢¹ÚÀÌ¸é ±¦ÂúÀº°Ç°¡... 2008/12/18  
operet Àü ´ÙÇàÈ÷µµ, ³ëÅÏ ÀÎÅͳݽÃÅ¥¸®Æ¼°¡ ¸·¾ÆÁÖ³×¿ä ¤¾¤¾ 2008/12/21  
cydstyle Àúµµ ³ëÅÏÀÌ..¤»¤» 2008/12/30  
dkdkfjgh ±Û°Ô¿ä ¿¢¹ÚÀε¥... 2009/01/05  
¶Ë¸¶·ç ¤¾..Àü ¾Æ¹«°ÍµÎ ¾È¶á´Ù´Â.. 2009/01/10  
¾çÆÄ <b>Glob</b> 2009/03/09  
eraseZEROne Internet Explorer ´©Àû º¸¾È ¾÷µ¥ÀÌÆ® (958215)
https://docs.microsoft.com/ko-kr/security-updates/securitybulletins/2008/ms08-073
2019/01/06  
  [Á¤º¸] MS Internet Explorer XML Parsing Remote Buffer overflow zer0-day[7]     sjh21a
12/17 9103
82   [Á¤º¸] FreeBSD 7.0-RELEASE ÅÚ³Ý µ¥¸ó ³»ºÎ ±ÇÇÑ »ó½Â Ãë¾àÁ¡ (¿ø°Ý °ø°Ý °¡´É)[6]     sjh21a
02/20 11747
81   [°øÁö] ÇØÄ¿½ºÄð4°¡ µåµð¾î ¿ÀǵǾú½À´Ï´Ù.^^[34]     ¸Û¸Û
09/01 12413
80   [°øÁö] ȸ¿ø °¡ÀÔÇϽŠºÐµé¸¸ ±ÛÀ» ÀÛ¼ºÇÏ½Ç ¼ö ÀÖ½À´Ï´Ù.[6]     ¸Û¸Û
09/01 8819
79   [°øÁö] ±âÁ¸ÀÇ ÇØÄ¿½ºÄð TEAM¿¡ ´ëÇÑ °øÁöÀÔ´Ï´Ù.[1]     ¸Û¸Û
09/01 9612
78   [°øÁö] FTZ ·¹º§Àº Á¶¸¸°£¿¡ º¹±¸µË´Ï´Ù.[8]     ¸Û¸Û
09/01 9177
77   [°øÁö] FTZ ·¹º§ Á¤º¸ º¹±¸ ¿Ï·áµÇ¾ú½À´Ï´Ù.[26]     ¸Û¸Û
09/02 9727
76   [°øÁö] ÇØÄð äÆÃ¹æ ¼³Ä¡°¡ ¿Ï·áµÇ¾ú½À´Ï´Ù.[30]     ¸Û¸Û
09/04 10533
75   [°øÁö] FTZ Çϵå¿þ¾î¸¦ ¾÷±×·¹À̵å ÇÏ¿´½À´Ï´Ù.[46]     ¸Û¸Û
02/14 13221
74   [°øÁö] ¸®´ª½º Ä¿³ÎÀÇ do_mremap() Ãë¾àÁ¡¿¡ ´ëÇÑ ±Ç°í¹®ÀÔ´Ï´Ù.[105]     ¸Û¸Û
01/27 23917
73   [°øÁö] ¿ÀÇ 3Áֳ⠱â³ä À̺¥Æ® ´ç÷ÀÚ ¹ßÇ¥!![69]     ¸Û¸Û
09/21 10949
72   [°øÁö] ¸®´ª½º Ä¿³ÎÀÇ do_brk() Ãë¾àÁ¡¿¡ ´ëÇÑ ±Ç°í¹® ÀÔ´Ï´Ù.[181]     ¸Û¸Û
12/18 18896
71   [°øÁö] Â÷ÈÄ ÇØÄ¿½ºÄð ¿î¿µ °èȹÀÔ´Ï´Ù.[82]     ¸Û¸Û
02/21 14273
70   [°øÁö] FTZ ¼­ºñ½º Á¡°Ë ÁßÀÔ´Ï´Ù.[39]     ¸Û¸Û
05/06 11849
69   [°øÁö] ÇØÄ¿½ºÄð ¾÷µ¥ÀÌÆ® ³»¿ëÀÔ´Ï´Ù.[39]     ¸Û¸Û
09/15 14654
68   [°øÁö] µµ¼­°ü ¼­ºñ½º¸¦ Àç¿ÀÇÂÇÏ¿´½À´Ï´Ù.[15]     ¸Û¸Û
04/30 9754
67   [°øÁö] ¿ù°£ ¿ì¼ö ȸ¿ø ¼±Á¤ ¾È³»ÀÔ´Ï´Ù.[43]     ¸Û¸Û
10/05 10314
66   [°øÁö] »çÀÌÆ® ¾÷µ¥ÀÌÆ® ÁøÇà »óȲÀÔ´Ï´Ù.[82]     ¸Û¸Û
01/09 17822
65   [°øÁö] 07³â 6, 7¿ù ¿ì¼ö ȸ¿ø ¼±Á¤ °á°úÀÔ´Ï´Ù.[71]     ¸Û¸Û
11/01 14400
64   [°øÁö] FTZ ¼­¹ö ÀÌÀü ¾È³»ÀÔ´Ï´Ù.[35]     ¸Û¸Û
09/27 13829
1 [2][3][4][5]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org