Ãë¾àÁ¡ID |
25028 |
À§Çèµµ |
40 |
Æ÷Æ® |
1343 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
DB |
»ó¼¼¼³¸í |
ÇØ´ç Microsoft SQL Server 2000Àº À߸øµÈ ·¹Áö½ºÆ®¸® Ű ÆÛ¹Ì¼Ç Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Microsoft SQL ¼¹ö 2000 ±×¸®°í SQL Server Desktop Engine (MSDE) 2000Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© »ó½ÂµÈ ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Microsoft SQL ¼¹ö´Â ´ë°³ ¼³Ä¡ ½Ã¿¡ ½Ã½ºÅÛ °ü¸®Àڵ鿡 ÀÇÇØ Á¤ÀÇµÈ "service account" ±ÇÇÑÀ¸·Î ½ÇÇàµÈ´Ù. ÀÌ Á¤ÀÇ´Â SQL ¼¹ö°¡ ·¹Áö½ºÆ®¸® Ű °ªÀÇ º¯°æÀÌ °¡´ÉÇÑ ÆÛ¹Ì¼ÇÀ» °¡Áö°í WindowsÀÇ ·¹Áö½ºÆ®¸®¿¡ ÀúÀåµÇ¾î ÀÖ´Ù. °á°úÀûÀ¸·Î "xp_regwrite"¶ó´Â Extended Stored Procedure¿¡ ´ëÇÑ ¾×¼¼½º ±ÇÇÑÀ» °¡Áø °ø°ÝÀÚµéÀº ±× ·¹Áö½ºÆ®¸® °ªÀ» º¯°æÇÏ¿© SQL ¼¹ö°¡ "service account"·Î LocalSystemÀ¸·Î ÀÛµ¿Çϵµ·Ï ÇÒ ¼ö ÀÖ´Ù. ¼¹ö È£½ºÆ®¸¦ ¸®ºÎÆÃÇϰųª SQL ¼ºñ½º¸¦ Àç½ÃÀÛÇϸé, SQL ¼¹ö´Â Localsystem °èÁ¤ÀÇ ¿ÏÀüÇÑ °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áö°í ÀÛµ¿ÇÏ°Ô µÈ´Ù. ÀÌ ´É·ÂÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿î¿µÃ¼Á¦ ±ÇÇÑÀ¸·Î ½Ã½ºÅÛ »ó¿¡ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Â SQL ÁúÀǹ®µéÀ» »ç¿ëÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
* ¾Ë¸²: ÀÌ Á¡°Ë Ç׸ñÀº Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ´ÜÁö ´ë»ó SQL ¼¹öÀÇ ¹è³Ê Á¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼, °ÅÁþ ¾ç¼º(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms02-034.asp http://www.cert.org/advisories/CA-2002-22.html http://www.kb.cert.org/vuls/id/796313
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft SQL Server 2000 Microsoft Desktop Engine (MSDE) 2000 Microsoft Windows Any version |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®·ÎºÎÅÍ °¡Àå ÃÖ½ÅÀÇ SQL ¼¹ö 2000 ¼ºñ½º ÆÑÀ» ±¸ÇÏ¿© ¼³Ä¡ÇÑ´Ù: http://support.microsoft.com/default.aspx?scid=kb;EN-US;290211 |
°ü·Ã URL |
CVE-2002-0642 (CVE) |
°ü·Ã URL |
5205 (SecurityFocus) |
°ü·Ã URL |
9523 (ISS) |
|