Ãë¾àÁ¡ID |
20050 |
À§Çèµµ |
30 |
Æ÷Æ® |
161 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
SNMP |
»ó¼¼¼³¸í |
»ç¿ë ÁßÀÎ UDP Æ÷Æ®µéÀÌ SNMP¸¦ ÅëÇØ ȹµæµÈ´Ù. Ȱµ¿ ÁßÀÎ Æ÷Æ®´Â ÀÎÀÔ È¤Àº ¼ÛÃâ ¼¼¼ÇÀ» ³ªÅ¸³»°Å³ª Á¢¼Ó ´ë±â ÁßÀÎ ¼ºñ½ºµéÀÌ ÀÖÀ½À» ³ªÅ¸³½´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÌ Á¤º¸¸¦ Á» ´õ ¼¼¹ÐÇÑ °ø°ÝÀ» ¼öÇàÇϴµ¥ ÀÌ¿ëÇÒ ¼ö ÀÖ´Ù
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: SNMP ¼ºñ½º¸¦ °¡µ¿ ÁßÀÎ ¸ðµç Ç÷§Æûµé |
ÇØ°áÃ¥ |
1. ¸¸¾à SNMP°¡ »ç¿ëȯ°æ¿¡¼ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é SNMP ¼ºñ½ºÀÇ ¿ÏÀüÇÑ ÀÛµ¿ÁßÁö¸¦ °í·ÁÇÏ¿©¾ß ÇÑ´Ù. - Solaris 10, Solaris 11: # svcadm disable svc:/application/management/snmpdx - Enterprise Linux 6.4, CentOS 6.4, Fedora 19: # /etc/init.d/snmpd stop # rpm -e (snmp name)
2. ½Å·Ú¼º¾ø´Â È£½ºÆ®µé·ÎºÎÅÍÀÇ µé¾î¿À´Â ¸ðµç SNMP Æ®·¡ÇÈ(ports 161°ú 162 UDP)À» ÇÊÅ͸µÇÑ´Ù.
3. µðÆúÆ® Community StringµéÀ» º¯°æÇÑ´Ù. ´ëºÎºÐÀÇ SNMP°¡ ÀÛµ¿ÇÏ´Â Á¦Ç°µé¿¡´Â ÀбâÀü¿ëÀÇ "public" °ú Àб⾲±â ¾×¼¼½º°¡ °¡´ÉÇÑ "private"ÀÇ µðÆúÆ® Community StringÀÌ ¼³Á¤µÇ¾î ÀÖ´Ù. ³×Æ®¿÷ °ü¸®ÀÚµéÀº À̵é Community StringµéÀ» ÀڽŵéÀÌ Á¤ÀÇÇÑ ¾î¶² °ÍÀ¸·Î ¹Ù²Ù¾î¾ß ÇÑ´Ù.
4. ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿© ÆÐÄ¡³ª ¾÷±×·¹À̵尡 ÀÖ´ÂÁö ¾Ë¾Æº»´Ù. CERT ±Ç°í¾È CA-2002-03¿¡´Â ¸¹Àº SNMP º¥´õµéÀ» À§ÇÑ Ãë¾àÁ¡µé°ú ¾÷µ¥ÀÌÆ®µé¿¡ °üÇÑ ±¸Ã¼ÀûÀÎ Á¤º¸°¡ ÀÖ´Ù. ÀÌ ¹®¼´Â ´ÙÀ½ »çÀÌÆ®¿¡¼ ÂüÁ¶ °¡´ÉÇÏ´Ù: http://www.cert.org/advisories/CA-2002-03.html |
°ü·Ã URL |
CVE-1999-0615 (CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|