Ãë¾àÁ¡ID |
26069 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â 'Ư¼öÇÑ È®Àå ¸í·É(verb) ¿äûÀ» ÅëÇÑ Exchange ¼¹ö »óÀÇ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡'¿¡ ´ëÇÑ Hotfix(KB829436)ÀÌ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. MS Exchange´Â SMTP ÇÁ·ÎÅäÄÝ Áö¿ø »Ó¸¸ ¾Æ´Ï¶ó °ÈµÈ ÀüÀÚ¸ÞÀÏ ¼ºñ½º¸¦ Á¦°øÇÏ´Â ¸¹ÀÌ »ç¿ëµÇ´Â ÅëÇÕ Á¦Ç°ÀÌ´Ù. Exchange´Â SMTP È®Àå ¸í·Éµé(verbs)À» ÅëÇØ¼ Exchange ¼¹ö °£ÀÇ Æ¯º°ÇÑ Ã³¸® ¸í·ÉµéÀ» Àü´ÞÇÑ´Ù. ±×·¯³ª, ÀÌ Exchange 5.5 ¿Í Exchange 2000 ¼ºñ½º¿¡¼´Â ºÎÀûÀýÇÑ °æ°è °Ë»ç·Î ÀÎÇÏ¿© È®Àå ¸í·É ¿äûÀ» ÅëÇÑ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡ÀÌ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. ºñÀΰ¡µÈ °ø°ÝÀÚµéÀº Exchange SMTP Æ÷Æ®¿¡ Á¢¼ÓÇÑ ÈÄ Àß Á¶ÀÛµÈ È®Àå ¸í·É ¿äûÀ» Àü´ÞÇÔÀ¸·Î½á, ¹öÆÛ ¿À¹öÇ÷ο츦 ÀÏÀ¸Å³ ¼ö ÀÖ´Ù. À̸¦ ÅëÇØ SMTP ¼¹ö°¡ Á¾·áÇϰųª SMTP ¼ºñ½º ±ÇÇÑÀ¸·Î °ø°ÝÀÚÀÇ Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/MS03-046.asp http://www.kb.cert.org/vuls/id/422156
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Exchange Server 5.5, ¼ºñ½º ÆÑ 4 Microsoft Exchange Server 2000, ¼ºñ½º ÆÑ 3 Windows 2000 Any version Windows NT Any version Windows XP Any version |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ º¸¾È °Ô½ÃÆÇ MS03-046¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/MS03-046.asp
-- ¶Ç´Â --
Àӽà Á¶Ä¡ ¹æ¹ýÀ¸·Î, ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© Exchange¿¡ µðÆúÆ®·Î Á¸ÀçÇÏ´Â ISA publishing ·êÀ» »ç¿ëÇÏ¿© STMP ÇÁ·ÎÅäÄÝ È®ÀåÀ» ÇÊÅ͸µÇÑ´Ù: http://support.microsoft.com/default.aspx?scid=kb;en-us;311237
-- ¶Ç´Â --
ÀÎÁõµÈ SMTP ¼¼¼Ç¸¸ ¿¬°áÀ» ¼ö¶ôÇÑ´Ù. Exchange 2000ÀÇ °æ¿ì, 1. Exchange ½Ã½ºÅÛ °ü¸®ÀÚ(System Manager)¸¦ ½ÃÀÛ ÈÄ ÇØ´ç ¼¹ö¸¦ ã´Â´Ù. 2. ¼¹öÀÇ "Protocol" ÄÁÅ×À̳ʸ¦ È®ÀåÇÑ ÈÄ "SMTP" ÄÁÅ×À̳ʸ¦ È®ÀåÇÑ´Ù. 3. °¢°¢ÀÇ SMTP °¡»ó ¼¹ö¸¦ À§Çؼ, - °¡»ó ¼¹öÀÇ "µî·ÏÁ¤º¸"¸¦ ¿°í "Access" ÅÇÀ» Ŭ¸¯ÇÑ´Ù. - "Authentication" ¹öưÀ» Ŭ¸¯Çϰí "Anonymous Access" üũ¹Ú½º¸¦ ÇØÁ¦ÇÑ´Ù.
Exchange 5.5ÀÇ °æ¿ì, 1. "Connection" ÆäÀÌÁö¸¦ Ŭ¸¯ÇÑ´Ù. 2. "Accept Connections" ¼½¼Ç¿¡¼, "Only from hosts using Authentication." ¶óµð¿À ¹öưÀ» üũÇÑ´Ù.
-- ¶Ç´Â --
¹æÈº®À» ÅëÇØ SMTP °¡ »ç¿ëÇÏ´Â Æ÷Æ®(25)·ÎÀÇ Æ®·¡ÇÈÀ» Â÷´ÜÇÑ´Ù. |
°ü·Ã URL |
CVE-2003-0714 (CVE) |
°ü·Ã URL |
8838 (SecurityFocus) |
°ü·Ã URL |
13432 (ISS) |
|