English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 17068
À§Çèµµ 40
Æ÷Æ® 111
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù RPC
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡´Â nfsd µ¥¸óÀÌ °¡µ¿ÁßÀÌ¸ç ¾î¶² ÆÄÀϽýºÅ۵鵵 Export Çϰí ÀÖÁö ¾Ê´Ù. ÇÊ¿äÇÏÁö ¾Ê´Ù¸é °¡µ¿ÇÏÁö ¾Ê´Â ÁÁ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/327.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
NFS ¸ðµç ¹öÀü
ÇØ°áÃ¥ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é NFS ´ë¸óÀ» °¡µ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù. Nfsd´Â ´ëºÎºÐ rc ½ºÅ©¸³Æ®·ÎºÎÅÍ ½ÃÀ۵Ǵµ¥ °£È¤ /etc/inetd.conf ÆÄÀÏ¿¡¼­ ½ÃÀÛµÉ ¼öµµ ÀÖ´Ù.

RC ½ºÅ©¸³Æ®·ÎºÎÅÍ ´ë¸óÀ» Disable ½Ã۱â À§Çؼ­´Â ¿î¿µÃ¼Á¦¿¡ µû¶ó ÀûÀýÇÏ°Ô ÁÖ¼®Ã³¸® ÇÏ¿©¾ß ÇÑ´Ù. ¿¹¸¦µé¾î, SunOS 5.x ¿¡¼­ nfsd¸¦ DisableÇϱâ À§Çؼ­´Â ´ÙÀ½°ú °°Àº ¸í·ÉµéÀ» ½ÇÇà½ÃÄÑ¾ß ÇÑ´Ù:

# /etc/init.d/nfs.server stop
# mv /etc/init.d/nfs.server /etc/init.d/DISABLED_nfs.server

inetd.conf ÆÄÀÏ¿¡¼­ ´ë¸óÀ» Disable ½Ã۱â À§Çؼ­´Â:

1. /etc/inetd.conf (ȤÀº °°Àº ¿ªÇÒÀ» ÇÏ´Â) ÆÄÀÏÀ» ÆíÁýÇÑ´Ù.
2. ´ë¸óÀ» Á¦¾îÇÏ´Â ¶óÀÎÀ» ã´Â´Ù.
3. ´ë¸óÀ» ÁÖ¼®Ã³¸® Çϱâ À§ÇØ ¶óÀÎÀÇ ¸Ç ¾Õ¿¡ #¸¦ ³Ö´Â´Ù.
4. inetd ´ë¸óÀ» Àç½ÃÀÛÇÑ´Ù.

Solaris 10, Solaris 11ÀÇ °æ¿ì:
# svcadm disable svc:/network/nfs/server:default

Enterprise Linux 6.4, CentOS 6.4, Fedora 19ÀÇ °æ¿ì:
# /sbin/service nfs stop
# mv /etc/init.d/nfs.server /etc/init.d/DISABLED_nfs.server
°ü·Ã URL CVE-1999-0548 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)