English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18056
À§Çèµµ 40
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í ÇØ´ç Windows Exchange SMTP ¼­ºñ½º¿¡´Â Ư¼öÇÏ°Ô Á¶ÀÛµÈ È®Àå ¸í·É(verb) ¿äûÀ» ÅëÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
MS Exchange´Â SMTP ÇÁ·ÎÅäÄÝ Áö¿ø »Ó¸¸ ¾Æ´Ï¶ó °­È­µÈ ÀüÀÚ¸ÞÀÏ ¼­ºñ½º¸¦ Á¦°øÇÏ´Â ¸¹ÀÌ »ç¿ëµÇ´Â ÅëÇÕ Á¦Ç°ÀÌ´Ù. Exchange´Â SMTP È®Àå ¸í·Éµé(verbs)À» ÅëÇØ¼­ Exchange ¼­¹ö °£ÀÇ Æ¯º°ÇÑ Ã³¸® ¸í·ÉµéÀ» Àü´ÞÇÑ´Ù. ±×·¯³ª, ÀÌ Exchange 5.5 ¿Í Exchange 2000 ¼­ºñ½º¿¡¼­´Â ºÎÀûÀýÇÑ °æ°è °Ë»ç·Î ÀÎÇÏ¿© È®Àå ¸í·É ¿äûÀ» ÅëÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ºñÀΰ¡µÈ °ø°ÝÀÚµéÀº Exchange SMTP Æ÷Æ®¿¡ Á¢¼ÓÇÑ ÈÄ Àß Á¶ÀÛµÈ È®Àå ¸í·É ¿äûÀ» Àü´ÞÇÔÀ¸·Î½á, ¹öÆÛ ¿À¹öÇ÷ο츦 ÀÏÀ¸Å³ ¼ö ÀÖ´Ù. À̸¦ ÅëÇØ SMTP ¼­¹ö°¡ Á¾·áÇϰųª SMTP ¼­ºñ½º ±ÇÇÑÀ¸·Î °ø°ÝÀÚÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/MS03-046.asp
http://www.kb.cert.org/vuls/id/422156

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Exchange Server 5.5, ¼­ºñ½º ÆÑ 4
Microsoft Exchange Server 2000, ¼­ºñ½º ÆÑ 3
Microsoft Windows Any version
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ º¸¾È °Ô½Ã¹° MS03-046À» ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/MS03-046.asp

-- ¶Ç´Â --

Àӽà Á¶Ä¡ ¹æ¹ýÀ¸·Î,
´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© Exchange¿¡ µðÆúÆ®·Î Á¸ÀçÇÏ´Â ISA publishing ·êÀ» »ç¿ëÇÏ¿© STMP ÇÁ·ÎÅäÄÝ È®ÀåÀ» ÇÊÅ͸µÇÑ´Ù:
http://support.microsoft.com/default.aspx?scid=kb;en-us;311237

-- ¶Ç´Â --

ÀÎÁõµÈ SMTP ¼¼¼Ç¸¸ ¿¬°áÀ» ¼ö¶ôÇÑ´Ù.
Exchange 2000ÀÇ °æ¿ì,
1. Exchange ½Ã½ºÅÛ °ü¸®ÀÚ(System Manager)¸¦ ½ÃÀÛ ÈÄ ÇØ´ç ¼­¹ö¸¦ ã´Â´Ù.
2. ¼­¹öÀÇ "Protocol" ÄÁÅ×À̳ʸ¦ È®ÀåÇÑ ÈÄ "SMTP" ÄÁÅ×À̳ʸ¦ È®ÀåÇÑ´Ù.
3. °¢°¢ÀÇ SMTP °¡»ó ¼­¹ö¸¦ À§Çؼ­,
- °¡»ó ¼­¹öÀÇ "µî·ÏÁ¤º¸"¸¦ ¿­°í "Access" ÅÇÀ» Ŭ¸¯ÇÑ´Ù.
- "Authentication" ¹öưÀ» Ŭ¸¯Çϰí "Anonymous Access" üũ¹Ú½º¸¦ ÇØÁ¦ÇÑ´Ù.

Exchange 5.5ÀÇ °æ¿ì,
1. "Connection" ÆäÀÌÁö¸¦ Ŭ¸¯ÇÑ´Ù.
2. "Accept Connections" ¼½¼Ç¿¡¼­, "Only from hosts using Authentication." ¶óµð¿À ¹öưÀ» üũÇÑ´Ù.

-- ¶Ç´Â --

¹æÈ­º®À» ÅëÇØ SMTP °¡ »ç¿ëÇÏ´Â Æ÷Æ®(25/tcp)·ÎÀÇ Æ®·¡ÇÈÀ» Â÷´ÜÇÑ´Ù.
°ü·Ã URL CVE-2003-0714 (CVE)
°ü·Ã URL 8838 (SecurityFocus)
°ü·Ã URL 13432 (ISS)