English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 20050
À§Çèµµ 30
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù SNMP
»ó¼¼¼³¸í »ç¿ë ÁßÀÎ UDP Æ÷Æ®µéÀÌ SNMP¸¦ ÅëÇØ ȹµæµÈ´Ù. Ȱµ¿ ÁßÀÎ Æ÷Æ®´Â ÀÎÀÔ È¤Àº ¼ÛÃâ ¼¼¼ÇÀ» ³ªÅ¸³»°Å³ª Á¢¼Ó ´ë±â ÁßÀÎ ¼­ºñ½ºµéÀÌ ÀÖÀ½À» ³ªÅ¸³½´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Á¤º¸¸¦ Á» ´õ ¼¼¹ÐÇÑ °ø°ÝÀ» ¼öÇàÇϴµ¥ ÀÌ¿ëÇÒ ¼ö ÀÖ´Ù

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SNMP ¼­ºñ½º¸¦ °¡µ¿ ÁßÀÎ ¸ðµç Ç÷§Æûµé
ÇØ°áÃ¥ 1. ¸¸¾à SNMP°¡ »ç¿ëȯ°æ¿¡¼­ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é SNMP ¼­ºñ½ºÀÇ ¿ÏÀüÇÑ ÀÛµ¿ÁßÁö¸¦ °í·ÁÇÏ¿©¾ß ÇÑ´Ù.
- Solaris 10, Solaris 11:
# svcadm disable svc:/application/management/snmpdx
- Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
# /etc/init.d/snmpd stop
# rpm -e (snmp name)

2. ½Å·Ú¼º¾ø´Â È£½ºÆ®µé·ÎºÎÅÍÀÇ µé¾î¿À´Â ¸ðµç SNMP Æ®·¡ÇÈ(ports 161°ú 162 UDP)À» ÇÊÅ͸µÇÑ´Ù.

3. µðÆúÆ® Community StringµéÀ» º¯°æÇÑ´Ù.
´ëºÎºÐÀÇ SNMP°¡ ÀÛµ¿ÇÏ´Â Á¦Ç°µé¿¡´Â ÀбâÀü¿ëÀÇ "public" °ú Àб⾲±â ¾×¼¼½º°¡ °¡´ÉÇÑ "private"ÀÇ µðÆúÆ® Community StringÀÌ ¼³Á¤µÇ¾î ÀÖ´Ù. ³×Æ®¿÷ °ü¸®ÀÚµéÀº À̵é Community StringµéÀ» ÀڽŵéÀÌ Á¤ÀÇÇÑ ¾î¶² °ÍÀ¸·Î ¹Ù²Ù¾î¾ß ÇÑ´Ù.

4. ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵尡 ÀÖ´ÂÁö ¾Ë¾Æº»´Ù. CERT ±Ç°í¾È CA-2002-03¿¡´Â ¸¹Àº SNMP º¥´õµéÀ» À§ÇÑ Ãë¾àÁ¡µé°ú ¾÷µ¥ÀÌÆ®µé¿¡ °üÇÑ ±¸Ã¼ÀûÀÎ Á¤º¸°¡ ÀÖ´Ù. ÀÌ ¹®¼­´Â ´ÙÀ½ »çÀÌÆ®¿¡¼­ ÂüÁ¶ °¡´ÉÇÏ´Ù:
http://www.cert.org/advisories/CA-2002-03.html
°ü·Ã URL CVE-1999-0615 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)