English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 13010
À§Çèµµ 30
Æ÷Æ® 1701
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù L2TP
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â L2TP(Layer 2 Tunneling Protocol) ¼­ºñ½º°¡ µ¿ÀÛ ÁßÀÌ´Ù.
½Ã½ºÄÚ Á¦Ç°¿¡ ÁַΠžÀçµÇ¾ú´ø L2TP(Layer 2 Tunneling Protocol) ÇÁ·ÎÅäÄÝÀº ÀÎÅͳݰú °°Àº °ø°ø ¸Á¿¡¼­ VPN(Virtual Private Network)À» ±¸ÃàÇϱâ À§ÇØ »ç¿ëµÇ´Â PPTP(Point-to-Point Tunneling Protocol) ÇÁ·ÎÅäÄÝÀÇ È®ÀåÀÌ´Ù. ÀÌ ÇÁ·ÎÅäÄÝÀº ½Ã½ºÄÚ L2F(Layer 2 Forwarding)¿Í ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® PPTP(Point-to-Point Tunneling Protocol) ÇÁ·ÎÅäÄÝÀÇ °áÇÕÀ¸·Î ÀÌ·ç¾îÁ³´Ù. L2TP ¸¦ ±¸¼ºÇÏ´Â µÎ °¡Áö ÁÖ¿ä ÄÄÆ÷³ÍÆ®·Î´Â ¹°¸®ÀûÀ¸·Î ÄÝ(Call)À» Á¾·áÇÏ´Â µð¹ÙÀ̽º L2TP Access Concentrator(LAC)¿Í PPP ½ºÆ®¸²À» ÀÎÁõÇϰí Á¾·áÇÏ´Â µð¹ÙÀ̽º L2TP Network Server(LNs) ÀÌ ÀÖ´Ù. ÀÌ·¯ÇÑ L2TP ¼­ºñ½º¿¡Á¸ÀçÇÏ´Â ÀϺΠº¸¾È »óÀÇ Ãë¾àÁ¡µéÀÌ º¸°í µÇ¾ú´Ù. ¿¹¸¦ µé¾î, L2TP ¼­ºñ½º¿¡¼­ »ç¿ëµÇ´Â rand() ÇÔ¼öÀÇ °áÇÔÀº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ÀûÀýÇÑ response(ÀÀ´ä)À» ¸¸µé°í À̸¦ ÀÌ¿ëÇØ L2TP Á¾Á¡°ú ÀÎÁõµÈ ÅͳÎÀ» ¼º¸³ÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. ±×·¯¹Ç·Î, ¾ÈÀüÇÑ ¼­ºñ½º °¡µ¿À» À§Çؼ­ °¡Àå ÃֽйöÀüÀ» À¯ÁöÇÏ°í ¼­ºñ½º Æ÷Æ®¿¡ ´ëÇÑ ÀûÀýÇÑ ÇÊÅ͸µÀ» Àû¿ëÇØ¾ß ÇÑ´Ù.

* ¾Ë¸²: ÀÌ Ãë¾àÁ¡ Á¡°Ë Ç׸ñÀº ¿ø°Ý È£½ºÆ® »óÀÇ ¼­ºñ½º Æ÷Æ® 1701/UDP ¿¡ "Start Control Connection Request" ¸Þ½ÃÁö¸¦ Àü¼ÛÇÏ¿© Á¡°ËÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securitytracker.com/alerts/2002/Aug/1005050.html
http://www.networksorcery.com/enp/protocol/l2tp.htm

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Any version
Linux Any version
Unix Any version
ÇØ°áÃ¥ Ãֽм­ºñ½º ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇϰí ÀûÀýÇÑ ¹æÈ­º®À̳ª ÇÊÅ͸µ ¼ÒÇÁÆ®¿þ¾î¸¦ »ç¿ëÇÏ¿© ¼­ºñ½º Æ÷Æ® 1701/UDP Æ÷Æ®¸¦ ÇÊÅ͸µÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)