English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18045
À§Çèµµ 30
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í ÇØ´ç MS SMTP ¼­¹ö´Â ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ SMTP ¼­ºñ½º¸¦ À§ÇÑ ÀûÀýÇÑ ÀÎÁõÀýÂ÷¸¦ ¿ìȸÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.
SMTP ¼­ºñ½º´Â µðÆúÆ®·Î Windows 2000 ¼­¹ö Á¦Ç°±º°ú MS Exchange 5.5 IMC(Internet Mail Connector)ÀÇ ÀϺημ­ ¼³Ä¡µÈ´Ù. ±×·¯³ª, ÀÌ SMTP ¼­ºñ½º¿¡´Â ºñÀΰ¡µÈ »ç¿ëÀڵ鵵 ¾Æ¹«·± ÀÎÁõÀýÂ÷ ¾øÀÌ SMTP ¼­¹ö¿¡ ·Î±×ÀÎÇÒ ¼ö ÀÖ´Â °áÇÔÀÌ Á¸ÀçÇÑ´Ù. ÀϹÝÀûÀ¸·Î »ç¿ëÀÚµéÀº SMTP ¼­¹ö°¡ Áö¿øÇÏ´Â AUTH ¸í·É°ú ¿É¼Ç NTMLÀ» »ç¿ëÇÏ¿© NTML challenge-response¸¦ °ÅÄ£ ÈÄ ¼­¹ö¿¡ ´ëÇÑ ¾×¼¼½º ±ÇÇÑÀ» ¾ò°Ô µÈ´Ù. ÀÌ ¸ÞÄ¿´ÏÁòÀº »ç¿ëÀÚ°¡ ¿î¿µÃ¼Á¦ »óÀÇ NTML ÀÎÁõ °èÃþ(authentication layer)À¸·ÎºÎÅÍ ÀÎÁõ¿äûÀ» ¹Þ´Â Áï½Ã, »ç¿ëÀÚ¿¡°Ô ¾×¼¼½º¸¦ Çã¿ëÇϱâ Àü¿¡ ºÎ°¡ÀûÀÎ °ËÁõÀýÂ÷¸¦ °ÅÄ¡µµ·Ï µðÀÚÀεǾî ÀÖ´Ù. ±×·¯³ª, ÀÌ·¯ÇÑ ºÎ°¡ÀûÀÎ °ËÁõÀýÂ÷°¡ ¿Ã¹Ù¸£°Ô ¼öÇàµÇÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© Ãë¾àÁ¡ÀÌ »ý°Ü³­´Ù. ´ÙÀ½°ú ¿¹Á¦ ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ¿© ½ÇÁ¦·Î Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ ´ëÇÑ Å×½ºÆ®¸¦ ¼öÇàÇØ º¼ ¼ö ÀÖ´Ù:

% telnet X.X.X.X 25
....
220 .. Microsoft ESMTP MAIL Service, Version : ...
Helo domain.com
250 ... Hello [...]
AUTH NTLM TlRMTVNTUAABAAAAB4IAgAAAAAAAAAAAAAAAAAAAAAA=
334 TlRMTVNTUAACAAAAHAAcADAA.......
TlRMTVNTUAADAAAAAQABAEAAAAAAAAAAQQAAAAAAAABAAAAAAAAAAEAAAAAAAAAAQAAAAAAAAABBAAAABYIAAAA=
235 2.7.0 Authentication successfull

ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ SMTP ¼­ºñ½º¿¡ ´ëÇÑ ºñÀΰ¡µÈ »ç¿ëÀÚ ·¹º§(level) ¾×¼¼½º(access) ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ±×·¯³ª, ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ´Ù¸¥ »ç¿ëÀÚµéÀÇ E-Mail À» Àаųª ´Ù¸¥ »ç¿ëÀÚÀÇ À̸§À¸·Î E-MailÀ» ¹ß¼ÛÇÏ´Â µîÀÇ ÇàÀ§´Â ÇÒ ¼ö ¾øÀ¸¸ç ´ëºÎºÐÀº ÀÌ ¼­¹ö¸¦ ÅëÇØ¼­ ¸ÞÀÏ ¸±·¹ÀÌ(mail relay)¸¦ ¼öÇàÇϱâ À§ÇØ ÀÌ Ãë¾àÁ¡ÀÌ ÀÌ¿ëµÉ °ÍÀÌ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/MS02-011.asp
http://www.securityfocus.com/bid/4205

* ¿µÇâ ¹Þ´Â Ç÷§Æû:
Microsoft Exchange Server 5.5
Microsoft Exchange Server 5.5 SP1~SP4
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Advanced Server SP1~SP2
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Advanced Server SP1~SP2
Microsoft Windows 2000 Server
Microsoft Windows 2000 Server SP1~SP2
ÇØ°áÃ¥ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® »çÀÇ À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.

* MS Windows 2000 Advanced Server, Professional, Server ÀÇ °æ¿ì :
1. http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=1790 À¥ ÆäÀÌÁö¸¦ ¿ÀÇÂÇÑ´Ù.
2. "Change Language"¿¡¼­ "Korean" À» ¼±ÅÃÇÑ ÈÄ [Go] ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
3. Windows 2000 º¸¾È ÆÐÄ¡ SMTP ·Ñ¾÷À» ´Ù¿î¹Þ±â À§ÇØ [´Ù¿î·Îµå]¸¦ Ŭ¸¯ÇÑ´Ù.

* MS Exchange Server 5.5 ÀÇ °æ¿ì :
1. http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=8627 À¥ ÆäÀÌÁö¸¦ ¿ÀÇÂÇÑ´Ù.
2. Exchange 5.5 IMC Patch 2655.55 ¸¦ ´Ù¿î¹Þ±â À§ÇØ [Download]¸¦ Ŭ¸¯ÇÑ´Ù.
°ü·Ã URL CVE-2002-0054 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)