English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 17067
À§Çèµµ 40
Æ÷Æ® 111
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù RPC
»ó¼¼¼³¸í NFS·Î ExportµÈ ÆÄÀϽýºÅÛ»óÀÇ µð·ºÅ丮°¡ ¾²±â°¡´ÉÇÑ »ç¿ëÀÚ HomeÀ¸·Î ÀνĵȴÙ. NFS¸¦ ÀÌ¿ëÇÑ´Ù¸é ÀÌ »óȲÀº °ø°ÝÀÚ¿¡°Ô ¾î¶² ÆÄÀϵéÀ» Á¶ÀÛÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ¾×¼¼½º¸¦ ¾òÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ¾²±â°¡´ÉÇÑ µð·ºÅ丮¿¡ ´ëÇØ ´ÙÀ½°ú °°Àº ÆÄÀϵéÀÌ ÀÖ´ÂÁö¸¦ ã´Â´Ù: .login, .profile, .rhosts, .cshrc, .netrc. ÀÌ ÆÄÀϵéÀº ÀüÇüÀûÀ¸·Î °èÁ¤ÀÇ È¨ µð·ºÅ丮¿¡ Á¸ÀçÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/81.php
http://www.cert.org/advisories/CA-1994-15.html
http://www.cerias.purdue.edu/coast/satan-html/tutorials/vulnerability/unrestricted_NFS_export.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
NFS ¸ðµç ¹öÀü
ÇØ°áÃ¥ °¡´ÉÇϸé ÀбâÀü¿ëÀ¸·Î µð·ºÅ丮¸¦ Export ÇÏ¿©¾ß Çϸç, ÀûÀýÇÑ NFS Export ¸®½ºÆ®µéÀ» µÎ°í ½Å·Ú¼º Àִ ȣ½ºÆ®µé¿¡°Ô¸¸ ExportÇϵµ·Ï Àç¼³Á¤ÇÏ¿©¾ß ÇÑ´Ù. ´õ ÀÚ¼¼ÇÑ Á¤º¸¿¡ ´ëÇØ¼­´Â UNIX ½Ã½ºÅÛ¿¡ ÀÖ´Â ¸Å´º¾ó ÆäÀÌÁö¸¦ Âü°íÇ϶ó.

* NFS ¼­¹ö ¼Â¾÷°ú °ü·ÃÇÑ Âü°í »çÀÌÆ®:
http://www.redhat.com/mirrors/LDP/HOWTO/NFS-HOWTO/index.html
http://nfs.sourceforge.net/nfs-howto/
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)