English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26064
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â '¸Þ½ÅÀú ¼­ºñ½º¿¡ ÀÖ´Â ¹öÆÛ ¿À¹öÇ÷οì'¿¡ ´ëÇÑ Hotfix(KB828035)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. "¸Þ½ÅÀú ¼­ºñ½º(Messenger Service)"´Â ¸ðµç Windows NT, Windows 2000, ±×¸®°í Windows XP µ¥½ÃÅ©Åé ¹× ¼­¹ö»ó¿¡ µðÆúÆ®·Î ÀÛµ¿µÈ´Ù. ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® ¸Þ½ÅÀú ¼­ºñ½º´Â ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® MSN ¸Þ½ÅÀú¿Í´Â ¾Æ¹«·± °ü°è°¡ ¾ø´Ù. Ãë¾àÁ¡Àº ¸Þ½ÅÀú ¼­ºñ½º°¡ ÇÒ´çµÈ ¹öÆÛ·Î °Ç³×±â Àü¿¡ ¸Þ½ÃÁöÀÇ ±æÀ̰¡ Ÿ´çÇÑÁö¸¦ °Ë»çÇÏÁö ¾ÊÀ½À¸·Î ÀÎÇØ ¹ß»ýÇÑ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÌ Ãë¾àÁ¡À» ¼º°øÀûÀ¸·Î µµ¿ëÇÏ°Ô µÇ¸é ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ»ó¿¡ Local System ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù. ¶Ç´Â ¸Þ½ÅÀú ¼­ºñ½º¸¦ ÀÛµ¿ÁßÁö ½Ãų ¼öµµ ÀÖ´Ù.
(¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS03-026¿¡ ¼³¸íµÈ ¹Ù¿Í °°ÀÌ) MS-RPC Ãë¾àÁ¡°ú À¯»çÇÏ°Ô ¸Þ½ÅÀú ¼­ºñ½º´Â MS-RPC (Microsoft Remote Procedure Call)¸¦ ÅëÇØ ¾×¼¼½ºµÉ ¼öµµ ÀÖ´Ù. ÀÌ·¯ÇÑ ¼º°ÝÀÇ Ãë¾àÁ¡µéÀº "MS Blast/Blaster", "Nachi", ±×¸®°í "SQL Slammer"¿Í °°Àº ÀÎÅÍ³Ý ¿ú¿¡ ÀÇÇØ »ç¿ëµÉ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms03-043.asp

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows NT Workstation 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Service Pack 6a
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6
Microsoft Windows 2000, Service Pack 2
Microsoft Windows 2000, Service Pack 3, Service Pack 4
Microsoft Windows XP Gold, Service Pack 1
Microsoft Windows XP 64-bit Edition
Microsoft Windows XP 64-bit Edition Version 2003
Microsoft Windows Server 2003
Microsoft Windows Server 2003 64-bit Edition
ÇØ°áÃ¥ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ¸Þ½ÅÀú ¼­ºñ½º¸¦ ÀÛµ¿ÁßÁö ½ÃÄÑ¾ß ÇÑ´Ù. ¸Þ½ÅÀú ¼­ºñ½º¸¦ ÀÛµ¿ÁßÁö ½Ã۱â À§Çؼ­´Â ´ÙÀ½°ú °°Àº ÀýÂ÷¸¦ µû¸¥´Ù:

1. "½ÃÀÛ" ¸Þ´º·Î °¡¼­ "Á¦¾îÆÇ"À» Ŭ¸¯ÇÑ´Ù.
2. ½Ã½ºÅÛÀÇ ÇüÅÂ¿Í ¼³Á¤¿¡ µû¶ó "¼º´É ¹× " ¸Þ´º, ȤÀº "°ü¸® µµ±¸" ¸Þ´º¸¦ ã¾Æ°£´Ù.
3. "½Ã½ºÅÛ" ¸Þ´º¸¦ ã¾Æ°£´Ù.
4. "¼­ºñ½º" ¾ÆÀÌÄÜÀ» Ŭ¸¯ÇÑ´Ù.
5. À©µµ¿ì¿¡ ½Ã½ºÅÛ ¼­ºñ½ºÀÇ ¸®½ºÆ®°¡ ³ªÅ¸³¯ °ÍÀÌ´Ù. ½ºÅ©·ÑÀ» ¾Æ·¡·Î ¿òÁ÷¿© "Messenger"¶ó ¸í¸íµÈ ¼­ºñ½º¸¦ ã´Â´Ù. ÀÌ ¼­ºñ½º»ó¿¡¼­ ¸¶¿ì½º ¿À¸¥ÂÊ ¹öưÀ» Ŭ¸¯ÇÏ°í ÆË¾÷¸Þ´º¿¡¼­ "µî·Ï Á¤º¸"¸¦ ¼±ÅÃÇÑ´Ù.
6. "½ÃÀÛ À¯Çü" ¿·¿¡ ÀÖ´Â ´ÙÀ̾ó·Î±× ¹Ú½º¸¦ ÀÌ¿ëÇÏ¿© "»ç¿ë ¾ÈÇÔ"À» ¼±ÅÃÇÑ´Ù.
7. "¼­ºñ½º »óÅÂ" ¼­ºê¸Þ´º ¾Æ·¡¿¡¼­ "ÁßÁö" ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
8. "Àû¿ë"°ú "È®ÀÎ" ¹öưÀ» Ŭ¸¯ÇÑ´Ù. ±×·¯¸é ¼­ºñ½º´Â ÁßÁöµÇ°í "»ç¿ë ¾ÈÇÔ"À¸·Î ¹Ù²ð °ÍÀÌ´Ù.

-- ¶Ç´Â --

´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ º¸¾È °Ô½ÃÆÇ MS03-043À» ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms03-043.asp

1. ´ÙÀ½ÀÇ ÆäÀÌÁö¸¦ ¿¬´Ù:
Microsoft Windows NT Workstation 4.0, Service Pack 6aÀÇ °æ¿ì:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7597FCF4-6615-4074-9E46-A17D808ED38D
Microsoft Windows NT Server 4.0, Service Pack 6aÀÇ °æ¿ì:
http://www.microsoft.com/downloads/details.aspx?FamilyId=B1949456-996A-485A-9A28-79FD79F26A1B
Microsoft Windows NT Server 4.0, Terminal Server Edition, Service Pack 6ÀÇ °æ¿ì:
http://www.microsoft.com/downloads/details.aspx?FamilyId=64AB4B66-1A6E-4264-93A8-26CDB98B05A8
Microsoft Windows 2000, Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?FamilyId=A0061377-1683-4C13-9527-5534F6C7CF85
Microsoft Windows 2000, Service Pack 3, Service Pack 4ÀÇ °æ¿ì:
http://www.microsoft.com/downloads/details.aspx?FamilyId=99F1B40D-906A-4945-A021-4B494CCCBDE0
Microsoft Windows XP Gold, Service Pack 1ÀÇ °æ¿ì:
http://www.microsoft.com/downloads/details.aspx?FamilyId=F02DA309-4B0A-4438-A0B9-5B67414C3833
Microsoft Windows XP 64-bit EditionÀÇ °æ¿ì:
http://www.microsoft.com/downloads/details.aspx?FamilyId=2BE95254-4C65-4CA5-80A5-55FDF5AA2296
Microsoft Windows XP 64-bit Edition Version 2003ÀÇ °æ¿ì:
http://www.microsoft.com/downloads/details.aspx?FamilyId=8B990946-84C8-4C91-899C-5A44EC13174E
Microsoft Windows Server 2003ÀÇ °æ¿ì:
http://www.microsoft.com/downloads/details.aspx?FamilyId=1DF106F3-7EC4-4EB0-9143-C1E3C9E2F5F8
Microsoft Windows Server 2003 64-bit EditionÀÇ °æ¿ì:
http://www.microsoft.com/downloads/details.aspx?FamilyId=8B990946-84C8-4C91-899C-5A44EC13174E
2. ¾ð¾î ¼±Åà ¸ñ·Ï¿¡¼­ ÇØ´ç ¾ð¾î¸¦ ¼±ÅÃÇÑ ÈÄ <Go> ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
3. ÆÐÄ¡ ÆÄÀÏÀ» ´Ù¿î¹Þ±â À§ÇØ <Download> ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
4. ÆÐÄ¡¸¦ ¼³Ä¡Çϱâ À§ÇØ ÆÄÀÏÀ» ½ÇÇà½ÃŲ´Ù.
5. ¼³Ä¡¸¦ ¿Ï·áÇϱâ À§Çؼ­ ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÑ´Ù.

-- ¶Ç´Â --

Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.

´ÙÀ½Àº ÀüÇüÀûÀÎ MicrosoftÀÇ ³×Æ®¿öÅ· Æ÷Æ®µéÀÌ´Ù. ÀÌ ¸ðµç Æ÷Æ®µéÀº (°³ÀÎ ¹æÈ­º®À» Æ÷ÇÔÇÑ) ¹æÈ­º®¿¡¼­ °¡´ÉÇÑÇÑ ¾ö°ÝÇÏ°Ô ÅëÁ¦µÇ¾î¾ß ÇÑ´Ù:

135/tcp MS-RPC connection-oriented
135/u¿¡ MS-RPC datagrams
137/udp NetBIOS name resolution
138/udp NetBIOS/SMB datagrams
139/tcp NetBIOS/SMB connection-oriented
445/tcp SMB connection-oriented
445/udp SMB datagrams
°ü·Ã URL CVE-2003-0717 (CVE)
°ü·Ã URL 8826 (SecurityFocus)
°ü·Ã URL 13412 (ISS)