English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 17065
À§Çèµµ 30
Æ÷Æ® 111
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù RPC
»ó¼¼¼³¸í NFS·Î Á¢¼Ó°¡´ÉÇÑ ÇØ´ç µð·ºÅ丮´Â ÀÓÀÇÀÇ »ç¿ëÀÚ¿¡ ÀÇÇØ ¾²±â °¡´ÉÇÏ´Ù. À̰ÍÀº °ø°ÝÀÚ°¡ ÇØ´ç ½Ã½ºÅÛÀÇ ExportµÈ µð·ºÅ丮 »ó¿¡ ¾î¶² ÆÄÀϵéÀ» ¼öÁ¤, ¶Ç´Â »ý¼ºÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/84.php
http://www.cert.org/advisories/CA-1994-15.html
http://www.cerias.purdue.edu/coast/satan-html/tutorials/vulnerability/unrestricted_NFS_export.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
NFS ¸ðµç ¹öÀü
ÇØ°áÃ¥ °¡´ÉÇϸé ÀбâÀü¿ëÀ¸·Î µð·ºÅ丮¸¦ Export Çϰųª, ȤÀº ½Å·Ú¼º Àִ ȣ½ºÆ®µé¿¡°Ô¸¸ ExportÇϵµ·Ï ¼³Á¤À» ´Ù½Ã ÇÏ¿©¾ß ÇÑ´Ù. ´õ ÀÚ¼¼ÇÑ Á¤º¸¿¡ ´ëÇØ¼­´Â UNIX ½Ã½ºÅÛ¿¡ ÀÖ´Â ¸Å´º¾ó ÆäÀÌÁö¸¦ Âü°íÇ϶ó.

* NFS ¼­¹ö ¼Â¾÷°ú °ü·ÃÇÑ Âü°í »çÀÌÆ®:
http://www.redhat.com/mirrors/LDP/HOWTO/NFS-HOWTO/index.html
http://nfs.sourceforge.net/nfs-howto/server.html
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)