Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø ÀÎÅͳÝħÇØ»ç°í´ëÀÀÁö¿ø¼¾ÅÍ´Â ¡°ÀϺΠ¹öÁ¯ÀÇ Apache Tomcat Connector Mod_JK ¶óÀ̺귯¸®¿¡ ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ ¹ß°ßµÇ¾ú´Ù. »ç¿ëÀÚµéÀº ÁÖÀÇÇØ¾ß ÇÑ´Ù.
Ãë¾àÁ¡ÀÌ ¹ß°ßµÈ ½Ã½ºÅÛÀº ´ÙÀ½°ú °°´Ù.
Apache Software Foundation Tomcat 4.1.34
Apache Software Foundation Tomcat 5.5.20
Apache Software Foundation mod_jk 1.2.20
Apache Software Foundation mod_jk 1.2.19
¼¾ÅÍ °ü°èÀÚ´Â ¡°Ãë¾à ´ë»óÀÏ °æ¿ì, ¿ø°ÝÀÇ °ø°ÝÀÚ°¡ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ¾î ÁÖÀÇÇØ¾ß ÇÑ´Ù¡±°í ¹àÈ÷°í, ÇØ°á ¹æ¾ÈÀ¸·Î ¡°¿µÇâ ¹Þ´Â ½Ã½ºÅÛ °ü¸®ÀÚ´Â Âü°í»çÀÌÆ®[5]¸¦ Âü°íÇÏ¿© mod_jk 1.2.21 ÀÌ»óÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù¡±°í µ¡ºÙ¿´´Ù.
¡Þ¼Ò½º ¾÷±×·¹ÀÌµå ¹æ¹ý
-Apache 1.3 ¿î¿µ½Ã
[user@kisa] ~ $ cd /tmp
[user@kisa]~$wget
www.apache.org/dist/tomcat/tomcat-connectors/jk/source/jk-1.2.21/tomcat-connectors-1.2.21-src.tar.gz
[user@kisa] ~ $ tar xvzf tomcat-connectors-1.2.21-src.tar.gz
[user@kisa] ~ $ cd tomcat-connectors-1.2.21-src
[user@kisa] ~ $ cd native
[user@kisa] ~ $ ./configure --with-apxs=/usr/sbin/apxs
("whereis apxs" ¸¦ ÀÌ¿ëÇÏ¿© apxs À§Ä¡ È®ÀÎ )
[user@kisa] ~ $ make
[user@kisa] ~ $ cp ./apache-1.3/mod_jk.so /usr/lib/apache
(apache module directory È®ÀÎÈÄ ÇØ´ç µð·ºÅ丮¿¡ º¹»ç)
[user@kisa] ~ $ make clean
-Apache 2.X ¿î¿µ½Ã
[user@kisa] ~ $ cd /tmp
[user@kisa] ~ $ wget http://www.apache.org/dist/tomcat/tomcat-connectors/jk/source/jk-1.2.21/tomcat-connectors-1.2.21-src.tar.gz
[user@kisa] ~ $ tar xvzf tomcat-connectors-1.2.21-src.tar.gz
[user@kisa] ~ $ cd tomcat-connectors-1.2.21-src
[user@kisa] ~ $ cd native
[user@kisa] ~ $ ./configure --with-apxs=/usr/sbin/apxs2
[user@kisa] ~ $ make
[user@kisa] ~ $ cp ./apache-2.0/mod_jk.so /usr/lib/apache2
¡Þ¹ÙÀ̳ʸ® ¾÷±×·¹ÀÌµå ¹æ¹ý
´ÙÀ½ ¾Æ·¡ ¸µÅ©¿¡¼ °¢ ½Ã½ºÅÛ¿¡ ¸Â´Â ¹ÙÀ̳ʸ® ÆÄÀÏÀ» ´Ù¿î ¹Þ¾Æ ¸ðµâ µð·ºÅ丮¿¡ ¼³Ä¡
- Windows(32bit)
www.apache.org/dist/tomcat/tomcat-connectors/jk/binaries/win32/jk-1.2.21/
- Windows(64bit)
www.apache.org/dist/tomcat/tomcat-connectors/jk/binaries/win64/jk-1.2.21/
- Solaris
www.apache.org/dist/tomcat/tomcat-connectors/jk/binaries/solaris/jk-1.2.21/
- Netware
www.apache.org/dist/tomcat/tomcat-connectors/jk/binaries/netware/1.2.21/
- Linux
www.apache.org/dist/tomcat/tomcat-connectors/jk/binaries/linux/jk-1.2.21/
Ãë¾àÁ¡¿¡ ÀÇÇÑ ÇÇÇظ¦ ÁÙÀ̱â À§ÇÏ¿© °ü¸®ÀÚ´Â À¥¼ºñ½º¸¦ ÃÖ¼Ò ±ÇÇÑÀ¸·Î ¼ºñ½º
¡ÞÂü°í »çÀÌÆ®
www.securityfocus.com/archive/1/461734/30/0/threaded
tomcat.apache.org/connectors-doc/miscellaneous/changelog.html
www.securitytracker.com/alerts/2007/Mar/1017719.html
www.zerodayinitiative.com/advisories/ZDI-07-008.html
tomcat.apache.org/connectors-doc/webserver_howto/apache.html
¡Þ¿ë¾î Á¤¸®
Apache : APACHE Àç´Ü¿¡¼ °³¹ßÇÑ ¿ÀǼҽº ±â¹ÝÀÇ À¥¼¹ö
Tomcat : ¾ÆÆÄÄ¡ ¼ÒÇÁÆ®¿þ¾î Àç´ÜÀÇ ¾ÖÇø®ÄÉÀÌ¼Ç ¼¹ö·Î¼, ÀÚ¹Ù ¼ºí¸´À» ½ÇÇà½ÃÅ°°í JSP Äڵ尡 Æ÷ÇԵǾî ÀÖ´Â À¥ÆäÀÌÁö¸¦ ¸¸µé¾î ÁØ´Ù.
[±æ¹Î±Ç ±âÀÚ(reporter21@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>