Ãë¾àÁ¡ID |
18045 |
À§Çèµµ |
30 |
Æ÷Æ® |
25 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMTP |
»ó¼¼¼³¸í |
ÇØ´ç MS SMTP ¼¹ö´Â ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ SMTP ¼ºñ½º¸¦ À§ÇÑ ÀûÀýÇÑ ÀÎÁõÀýÂ÷¸¦ ¿ìȸÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. SMTP ¼ºñ½º´Â µðÆúÆ®·Î Windows 2000 ¼¹ö Á¦Ç°±º°ú MS Exchange 5.5 IMC(Internet Mail Connector)ÀÇ ÀϺημ ¼³Ä¡µÈ´Ù. ±×·¯³ª, ÀÌ SMTP ¼ºñ½º¿¡´Â ºñÀΰ¡µÈ »ç¿ëÀڵ鵵 ¾Æ¹«·± ÀÎÁõÀýÂ÷ ¾øÀÌ SMTP ¼¹ö¿¡ ·Î±×ÀÎÇÒ ¼ö ÀÖ´Â °áÇÔÀÌ Á¸ÀçÇÑ´Ù. ÀϹÝÀûÀ¸·Î »ç¿ëÀÚµéÀº SMTP ¼¹ö°¡ Áö¿øÇÏ´Â AUTH ¸í·É°ú ¿É¼Ç NTMLÀ» »ç¿ëÇÏ¿© NTML challenge-response¸¦ °ÅÄ£ ÈÄ ¼¹ö¿¡ ´ëÇÑ ¾×¼¼½º ±ÇÇÑÀ» ¾ò°Ô µÈ´Ù. ÀÌ ¸ÞÄ¿´ÏÁòÀº »ç¿ëÀÚ°¡ ¿î¿µÃ¼Á¦ »óÀÇ NTML ÀÎÁõ °èÃþ(authentication layer)À¸·ÎºÎÅÍ ÀÎÁõ¿äûÀ» ¹Þ´Â Áï½Ã, »ç¿ëÀÚ¿¡°Ô ¾×¼¼½º¸¦ Çã¿ëÇϱâ Àü¿¡ ºÎ°¡ÀûÀÎ °ËÁõÀýÂ÷¸¦ °ÅÄ¡µµ·Ï µðÀÚÀεǾî ÀÖ´Ù. ±×·¯³ª, ÀÌ·¯ÇÑ ºÎ°¡ÀûÀÎ °ËÁõÀýÂ÷°¡ ¿Ã¹Ù¸£°Ô ¼öÇàµÇÁö ¸øÇÔÀ¸·Î ÀÎÇÏ¿© Ãë¾àÁ¡ÀÌ »ý°Ü³´Ù. ´ÙÀ½°ú ¿¹Á¦ ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏ¿© ½ÇÁ¦·Î Ãë¾àÇÑ ½Ã½ºÅÛ¿¡ ´ëÇÑ Å×½ºÆ®¸¦ ¼öÇàÇØ º¼ ¼ö ÀÖ´Ù:
% telnet X.X.X.X 25 .... 220 .. Microsoft ESMTP MAIL Service, Version : ... Helo domain.com 250 ... Hello [...] AUTH NTLM TlRMTVNTUAABAAAAB4IAgAAAAAAAAAAAAAAAAAAAAAA= 334 TlRMTVNTUAACAAAAHAAcADAA....... TlRMTVNTUAADAAAAAQABAEAAAAAAAAAAQQAAAAAAAABAAAAAAAAAAEAAAAAAAAAAQAAAAAAAAABBAAAABYIAAAA= 235 2.7.0 Authentication successfull
ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ SMTP ¼ºñ½º¿¡ ´ëÇÑ ºñÀΰ¡µÈ »ç¿ëÀÚ ·¹º§(level) ¾×¼¼½º(access) ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ±×·¯³ª, ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ´Ù¸¥ »ç¿ëÀÚµéÀÇ E-Mail À» Àаųª ´Ù¸¥ »ç¿ëÀÚÀÇ À̸§À¸·Î E-MailÀ» ¹ß¼ÛÇÏ´Â µîÀÇ ÇàÀ§´Â ÇÒ ¼ö ¾øÀ¸¸ç ´ëºÎºÐÀº ÀÌ ¼¹ö¸¦ ÅëÇØ¼ ¸ÞÀÏ ¸±·¹ÀÌ(mail relay)¸¦ ¼öÇàÇϱâ À§ÇØ ÀÌ Ãë¾àÁ¡ÀÌ ÀÌ¿ëµÉ °ÍÀÌ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/MS02-011.asp http://www.securityfocus.com/bid/4205
* ¿µÇâ ¹Þ´Â Ç÷§Æû: Microsoft Exchange Server 5.5 Microsoft Exchange Server 5.5 SP1~SP4 Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Advanced Server SP1~SP2 Microsoft Windows 2000 Professional Microsoft Windows 2000 Advanced Server SP1~SP2 Microsoft Windows 2000 Server Microsoft Windows 2000 Server SP1~SP2 |
ÇØ°áÃ¥ |
¸¶ÀÌÅ©·Î¼ÒÇÁÆ® »çÀÇ À¥ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.
* MS Windows 2000 Advanced Server, Professional, Server ÀÇ °æ¿ì : 1. http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=1790 À¥ ÆäÀÌÁö¸¦ ¿ÀÇÂÇÑ´Ù. 2. "Change Language"¿¡¼ "Korean" À» ¼±ÅÃÇÑ ÈÄ [Go] ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 3. Windows 2000 º¸¾È ÆÐÄ¡ SMTP ·Ñ¾÷À» ´Ù¿î¹Þ±â À§ÇØ [´Ù¿î·Îµå]¸¦ Ŭ¸¯ÇÑ´Ù.
* MS Exchange Server 5.5 ÀÇ °æ¿ì : 1. http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=8627 À¥ ÆäÀÌÁö¸¦ ¿ÀÇÂÇÑ´Ù. 2. Exchange 5.5 IMC Patch 2655.55 ¸¦ ´Ù¿î¹Þ±â À§ÇØ [Download]¸¦ Ŭ¸¯ÇÑ´Ù. |
°ü·Ã URL |
CVE-2002-0054 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|