Ãë¾àÁ¡ID |
13010 |
À§Çèµµ |
30 |
Æ÷Æ® |
1701 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
L2TP |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â L2TP(Layer 2 Tunneling Protocol) ¼ºñ½º°¡ µ¿ÀÛ ÁßÀÌ´Ù. ½Ã½ºÄÚ Á¦Ç°¿¡ ÁַΠžÀçµÇ¾ú´ø L2TP(Layer 2 Tunneling Protocol) ÇÁ·ÎÅäÄÝÀº ÀÎÅͳݰú °°Àº °ø°ø ¸Á¿¡¼ VPN(Virtual Private Network)À» ±¸ÃàÇϱâ À§ÇØ »ç¿ëµÇ´Â PPTP(Point-to-Point Tunneling Protocol) ÇÁ·ÎÅäÄÝÀÇ È®ÀåÀÌ´Ù. ÀÌ ÇÁ·ÎÅäÄÝÀº ½Ã½ºÄÚ L2F(Layer 2 Forwarding)¿Í ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® PPTP(Point-to-Point Tunneling Protocol) ÇÁ·ÎÅäÄÝÀÇ °áÇÕÀ¸·Î ÀÌ·ç¾îÁ³´Ù. L2TP ¸¦ ±¸¼ºÇÏ´Â µÎ °¡Áö ÁÖ¿ä ÄÄÆ÷³ÍÆ®·Î´Â ¹°¸®ÀûÀ¸·Î ÄÝ(Call)À» Á¾·áÇÏ´Â µð¹ÙÀ̽º L2TP Access Concentrator(LAC)¿Í PPP ½ºÆ®¸²À» ÀÎÁõÇϰí Á¾·áÇÏ´Â µð¹ÙÀ̽º L2TP Network Server(LNs) ÀÌ ÀÖ´Ù. ÀÌ·¯ÇÑ L2TP ¼ºñ½º¿¡Á¸ÀçÇÏ´Â ÀϺΠº¸¾È »óÀÇ Ãë¾àÁ¡µéÀÌ º¸°í µÇ¾ú´Ù. ¿¹¸¦ µé¾î, L2TP ¼ºñ½º¿¡¼ »ç¿ëµÇ´Â rand() ÇÔ¼öÀÇ °áÇÔÀº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ÀûÀýÇÑ response(ÀÀ´ä)À» ¸¸µé°í À̸¦ ÀÌ¿ëÇØ L2TP Á¾Á¡°ú ÀÎÁõµÈ ÅͳÎÀ» ¼º¸³ÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. ±×·¯¹Ç·Î, ¾ÈÀüÇÑ ¼ºñ½º °¡µ¿À» À§Çؼ °¡Àå ÃֽйöÀüÀ» À¯ÁöÇÏ°í ¼ºñ½º Æ÷Æ®¿¡ ´ëÇÑ ÀûÀýÇÑ ÇÊÅ͸µÀ» Àû¿ëÇØ¾ß ÇÑ´Ù.
* ¾Ë¸²: ÀÌ Ãë¾àÁ¡ Á¡°Ë Ç׸ñÀº ¿ø°Ý È£½ºÆ® »óÀÇ ¼ºñ½º Æ÷Æ® 1701/UDP ¿¡ "Start Control Connection Request" ¸Þ½ÃÁö¸¦ Àü¼ÛÇÏ¿© Á¡°ËÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.securitytracker.com/alerts/2002/Aug/1005050.html http://www.networksorcery.com/enp/protocol/l2tp.htm
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Windows Any version Linux Any version Unix Any version |
ÇØ°áÃ¥ |
Ãֽмºñ½º ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇϰí ÀûÀýÇÑ ¹æÈº®À̳ª ÇÊÅ͸µ ¼ÒÇÁÆ®¿þ¾î¸¦ »ç¿ëÇÏ¿© ¼ºñ½º Æ÷Æ® 1701/UDP Æ÷Æ®¸¦ ÇÊÅ͸µÇØ¾ß ÇÑ´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|