English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25024
À§Çèµµ 40
Æ÷Æ® 1521
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç Oracle Database ¼­¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é Oracle Net Services¿¡ Link ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. µ¥ÀÌÅͺ£À̽º °èÁ¤À» °¡Áö°í ÀÖ´Â °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» ÀÌ¿ëÇÏ¿© Àüü µ¥ÀÌÅͺ£À̽º¿¡ ´ëÇÑ Á¦¾î±ÇÀ» ¾ò°Å³ª ½ÉÁö¾î ¹®Á¦°¡ Àִ ȣ½ºÆ®»óÀÇ ½©(shell)À» ¾ò¾î³¾ ¼öµµ ÀÖ´Ù.
ÀÌ Ãë¾àÁ¡Àº ´ÙÀ½°ú °°ÀÌ 'CREATE DATABASE LINK' ÁúÀǸ¦ °¡Áø Á¢¼Ó ¹®ÀÚ¿­¿¡ ¸Å¿ì ±ä Àμö¸¦ Á¦°øÇÔÀ¸·Î½á ¹ß»ýÇÑ´Ù:

CREATE DATABASE LINK ngss
CONNECT TO hr
IDENTIFIED BY hr
USING 'longstring'

µðÆúÆ®·Î 'CREATE DATABASE LINK' ±ÇÇÑÀº CONNECT ·Ñ(role)¿¡ ÇÒ´çµÇ¾î ÀÖÀ¸¸ç ´ëºÎºÐÀÇ Oracle °èÁ¤µé¿¡ ÀÌ ·ÑÀÇ ±ÇÇÑÀÌ ÇÒ´çµÇ¾î ÀÖ´Ù. ½ÉÁö¾î SCOTTÀ̳ª ADAMS¿Í °°Àº ³·Àº ±ÇÇÑÀÇ °èÁ¤µé Á¶Â÷µµ database linkµéÀ» »ý¼ºÇÒ ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ database link¸¦ »ý¼ºÇÏ°í ³­ ÈÄ, ¸µÅ©·ÎºÎÅÍ Select ¹®À» ½ÇÇàÇϸé:

select * from table@ngss

¿À¹öÇ÷ο찡 Ã˹ߵǰí, ½ºÅÃ»ó¿¡ ÀúÀåµÈ ¸®ÅÏ ÁÖ¼Ò°¡ µ¤¾î ¾º¾îÁø´Ù. À̰ÍÀº °ø°ÝÀÚ°¡ Oracle ÇÁ·Î¼¼½ºÀÇ Á¦¾î±ÇÀ» ¾òµµ·Ï ÇØ ÁÖ¸ç, ¶ÇÇÑ ÀÓÀÇÀÇ »ç¿ëÀÚ Á¦°ø Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Á¦°øµÈ ÄÚµå´Â Oracle µ¥ÀÌÅͺ£À̽º ¼­¹ö°¡ ÀÛµ¿ÇÏ´Â °èÁ¤ÀÇ ±ÇÇÑÀ¸·Î ½ÇÇàµÈ´Ù. Unix ±â¹Ý ½Ã½ºÅ۵鿡¼­´Â ÀüÇüÀûÀ¸·Î 'oracle' »ç¿ëÀÚÀ̸ç À©µµ¿ìÁî¿¡¼­´Â local SYSTEM »ç¿ëÀÚÀÌ´Ù. ÀüÀÚÀÇ °æ¿ì µ¥ÀÌÅÍ¿¡ ´ëÇÑ ¿ÏÀüÇÑ Àå¾ÇÀ» ÀǹÌÇϸç ÈÄÀÚÀÇ °æ¿ì´Â µ¥ÀÌÅÍ¿Í ¿î¿µÃ¼Á¦¿¡ ´ëÇÑ ¿ÏÀüÇÑ Àå¾ÇÀ» ÀǹÌÇÑ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Oracle ¼­¹öÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://archives.neohapsis.com/archives/bugtraq/2003-04/0360.html
http://www.securityfocus.com/archive/1/319914

* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû:
Oracle9i Release 2
Oracle9i Release 1
Oracle8i (8.1.x - ¸ðµç ¸±¸®Áîµé)
Oracle8 (8.0.x - ¸ðµç ¸±¸®Áîµé)
Oracle7 Release 7.3.x
ÇØ°áÃ¥ ÀÌ ¹®Á¦¿¡ ´ëÇÑ ÀáÁ¤Àû ÆÐÄ¡(ÀÏȸ¿ë ÆÐÄ¡)´Â ´ÙÀ½ Ãë¾àÇÑ µ¥ÀÌÅͺ£À̽º ¹öÀüµé¿¡ ´ëÇØ¼­ ÀÌ¿ë °¡´ÉÇÏ´Ù:
o Oracle 9i Release 2, version 9.2.0.2 (Windows Á¦¿Ü)
o Oracle 9i Release 1, version 9.0.1.4
o Oracle 8i Release 3, version 8.1.7.4
o Oracle8 Database, Version 8.0.6.3 (ºñÁö¿ø ¸±¸®ÁîÀ̱ä ÇÏÁö¸¸ ÆÐÄ¡°¡ Extended Maintenance Support °í°´¿ëÀ¸·Î ÀÌ¿ë °¡´ÉÇÏ´Ù.)

ÇöÀç 8.0.5.x, 8.1.5.x, 8.1.6.x, 7.3.x, ȤÀº Áö¿øµÇ´Â ¸±¸®ÁîµéÀÇ ´Ù¸¥ ÆÐÄ¡ ¼Âµé¿¡ ´ëÇÑ ÆÐÄ¡´Â ¾ø´Ù. À̵é ÀÏȸ¿ë ÆÐÄ¡µéÀ» ´Ù¿î·Îµå Çϱâ À§Çؼ­´Â:

1. Oracle Áö¿ø ¼­ºñ½º À¥ »çÀÌÆ®ÀÎ Metalink ( http://metalink.oracle.com )·Î °£´Ù.
2. Patches ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
3. "New Metalink Patch Search"¸¦ Ŭ¸¯ÇÑ´Ù. ¸¸¾à "Simple Search" ½ºÅ©¸°¿¡ ÀÖÁö ¾Ê´Ù¸é, "Simple Search" ½ºÅ©¸°À¸·Î °¡¾ßÇϹǷΠ"Simple" ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
4. À§ÀÇ Patch Availability Matrix¸¦ Âü°íÇÏ¿© ÇÊ¿äÇÑ ÆÐÄ¡ ¹øÈ£¸¦ ÆÄ¾ÇÇÑ´Ù.
5. "Search By" ¿É¼Ç¿¡ ÀÖ´Â ¸Þ´º¿¡¼­ "Patch Numbers(s)"¸¦ ¼±ÅÃÇÑ´Ù. ±×¸®°í ¹Ú½º ¾È¿¡ ÇÊ¿äÇÑ ÆÐÄ¡¹øÈ£¸¦ ÀÔ·ÂÇÑ´Ù.
6. "Go" ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
7. ÇÊ¿äÇÑ Ç÷§Æû°ú ¾ð¾î¸¦ ¼±ÅÃÇÑ´Ù.
8. "Download" ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
9. ±Ç°í: ºÎ°¡ÀûÀÎ Á¤º¸³ª ¸í·ÉÀº "View README" ¹öưÀ» Ŭ¸¯Çؼ­ º¼ ¼ö ÀÖ´Ù.

Ç÷§Æû¿¡ ´ëÇÑ ÆÐÄ¡°¡ Á¦°øµÇÁö ¾Ê´Â´Ù¸é ÆÐÄ¡ Á¦°ø¿©ºÎ¸¦ Á¤±âÀûÀ¸·Î Metalink¿¡¼­ ÀçÈ®ÀÎÇϰųª Oracle Support Services¸¦ üũÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0222 (CVE)
°ü·Ã URL 7453 (SecurityFocus)
°ü·Ã URL (ISS)