Ãë¾àÁ¡ID |
25024 |
À§Çèµµ |
40 |
Æ÷Æ® |
1521 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
DB |
»ó¼¼¼³¸í |
ÇØ´ç Oracle Database ¼¹öÀÇ ¹öÀü Á¤º¸¿¡ µû¸£¸é Oracle Net Services¿¡ Link ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. µ¥ÀÌÅͺ£À̽º °èÁ¤À» °¡Áö°í ÀÖ´Â °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» ÀÌ¿ëÇÏ¿© Àüü µ¥ÀÌÅͺ£À̽º¿¡ ´ëÇÑ Á¦¾î±ÇÀ» ¾ò°Å³ª ½ÉÁö¾î ¹®Á¦°¡ Àִ ȣ½ºÆ®»óÀÇ ½©(shell)À» ¾ò¾î³¾ ¼öµµ ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ´ÙÀ½°ú °°ÀÌ 'CREATE DATABASE LINK' ÁúÀǸ¦ °¡Áø Á¢¼Ó ¹®ÀÚ¿¿¡ ¸Å¿ì ±ä Àμö¸¦ Á¦°øÇÔÀ¸·Î½á ¹ß»ýÇÑ´Ù:
CREATE DATABASE LINK ngss CONNECT TO hr IDENTIFIED BY hr USING 'longstring'
µðÆúÆ®·Î 'CREATE DATABASE LINK' ±ÇÇÑÀº CONNECT ·Ñ(role)¿¡ ÇÒ´çµÇ¾î ÀÖÀ¸¸ç ´ëºÎºÐÀÇ Oracle °èÁ¤µé¿¡ ÀÌ ·ÑÀÇ ±ÇÇÑÀÌ ÇÒ´çµÇ¾î ÀÖ´Ù. ½ÉÁö¾î SCOTTÀ̳ª ADAMS¿Í °°Àº ³·Àº ±ÇÇÑÀÇ °èÁ¤µé Á¶Â÷µµ database linkµéÀ» »ý¼ºÇÒ ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ database link¸¦ »ý¼ºÇÏ°í ³ ÈÄ, ¸µÅ©·ÎºÎÅÍ Select ¹®À» ½ÇÇàÇϸé:
select * from table@ngss
¿À¹öÇ÷ο찡 Ã˹ߵǰí, ½ºÅÃ»ó¿¡ ÀúÀåµÈ ¸®ÅÏ ÁÖ¼Ò°¡ µ¤¾î ¾º¾îÁø´Ù. À̰ÍÀº °ø°ÝÀÚ°¡ Oracle ÇÁ·Î¼¼½ºÀÇ Á¦¾î±ÇÀ» ¾òµµ·Ï ÇØ ÁÖ¸ç, ¶ÇÇÑ ÀÓÀÇÀÇ »ç¿ëÀÚ Á¦°ø Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Á¦°øµÈ ÄÚµå´Â Oracle µ¥ÀÌÅͺ£À̽º ¼¹ö°¡ ÀÛµ¿ÇÏ´Â °èÁ¤ÀÇ ±ÇÇÑÀ¸·Î ½ÇÇàµÈ´Ù. Unix ±â¹Ý ½Ã½ºÅ۵鿡¼´Â ÀüÇüÀûÀ¸·Î 'oracle' »ç¿ëÀÚÀ̸ç À©µµ¿ìÁî¿¡¼´Â local SYSTEM »ç¿ëÀÚÀÌ´Ù. ÀüÀÚÀÇ °æ¿ì µ¥ÀÌÅÍ¿¡ ´ëÇÑ ¿ÏÀüÇÑ Àå¾ÇÀ» ÀǹÌÇϸç ÈÄÀÚÀÇ °æ¿ì´Â µ¥ÀÌÅÍ¿Í ¿î¿µÃ¼Á¦¿¡ ´ëÇÑ ¿ÏÀüÇÑ Àå¾ÇÀ» ÀǹÌÇÑ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç Oracle ¼¹öÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://archives.neohapsis.com/archives/bugtraq/2003-04/0360.html http://www.securityfocus.com/archive/1/319914
* ¿µÇâÀ» ¹ÌÄ¡´Â Ç÷§Æû: Oracle9i Release 2 Oracle9i Release 1 Oracle8i (8.1.x - ¸ðµç ¸±¸®Áîµé) Oracle8 (8.0.x - ¸ðµç ¸±¸®Áîµé) Oracle7 Release 7.3.x |
ÇØ°áÃ¥ |
ÀÌ ¹®Á¦¿¡ ´ëÇÑ ÀáÁ¤Àû ÆÐÄ¡(ÀÏȸ¿ë ÆÐÄ¡)´Â ´ÙÀ½ Ãë¾àÇÑ µ¥ÀÌÅͺ£À̽º ¹öÀüµé¿¡ ´ëÇØ¼ ÀÌ¿ë °¡´ÉÇÏ´Ù: o Oracle 9i Release 2, version 9.2.0.2 (Windows Á¦¿Ü) o Oracle 9i Release 1, version 9.0.1.4 o Oracle 8i Release 3, version 8.1.7.4 o Oracle8 Database, Version 8.0.6.3 (ºñÁö¿ø ¸±¸®ÁîÀ̱ä ÇÏÁö¸¸ ÆÐÄ¡°¡ Extended Maintenance Support °í°´¿ëÀ¸·Î ÀÌ¿ë °¡´ÉÇÏ´Ù.)
ÇöÀç 8.0.5.x, 8.1.5.x, 8.1.6.x, 7.3.x, ȤÀº Áö¿øµÇ´Â ¸±¸®ÁîµéÀÇ ´Ù¸¥ ÆÐÄ¡ ¼Âµé¿¡ ´ëÇÑ ÆÐÄ¡´Â ¾ø´Ù. À̵é ÀÏȸ¿ë ÆÐÄ¡µéÀ» ´Ù¿î·Îµå Çϱâ À§Çؼ´Â:
1. Oracle Áö¿ø ¼ºñ½º À¥ »çÀÌÆ®ÀÎ Metalink ( http://metalink.oracle.com )·Î °£´Ù. 2. Patches ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 3. "New Metalink Patch Search"¸¦ Ŭ¸¯ÇÑ´Ù. ¸¸¾à "Simple Search" ½ºÅ©¸°¿¡ ÀÖÁö ¾Ê´Ù¸é, "Simple Search" ½ºÅ©¸°À¸·Î °¡¾ßÇϹǷΠ"Simple" ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 4. À§ÀÇ Patch Availability Matrix¸¦ Âü°íÇÏ¿© ÇÊ¿äÇÑ ÆÐÄ¡ ¹øÈ£¸¦ ÆÄ¾ÇÇÑ´Ù. 5. "Search By" ¿É¼Ç¿¡ ÀÖ´Â ¸Þ´º¿¡¼ "Patch Numbers(s)"¸¦ ¼±ÅÃÇÑ´Ù. ±×¸®°í ¹Ú½º ¾È¿¡ ÇÊ¿äÇÑ ÆÐÄ¡¹øÈ£¸¦ ÀÔ·ÂÇÑ´Ù. 6. "Go" ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 7. ÇÊ¿äÇÑ Ç÷§Æû°ú ¾ð¾î¸¦ ¼±ÅÃÇÑ´Ù. 8. "Download" ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 9. ±Ç°í: ºÎ°¡ÀûÀÎ Á¤º¸³ª ¸í·ÉÀº "View README" ¹öưÀ» Ŭ¸¯Çؼ º¼ ¼ö ÀÖ´Ù.
Ç÷§Æû¿¡ ´ëÇÑ ÆÐÄ¡°¡ Á¦°øµÇÁö ¾Ê´Â´Ù¸é ÆÐÄ¡ Á¦°ø¿©ºÎ¸¦ Á¤±âÀûÀ¸·Î Metalink¿¡¼ ÀçÈ®ÀÎÇϰųª Oracle Support Services¸¦ üũÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2003-0222 (CVE) |
°ü·Ã URL |
7453 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|