English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28039
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡ ÀÖ´Â Winsock Proxy¿Í ISA Firewall ¼­¹ö´Â ¼­ºñ½º °ÅºÎ °ø°Ý¿¡ Ãë¾àÇÏ´Ù.
Proxy ¼­¹ö´Â Ŭ¶óÀÌ¾ðÆ® ÄÄÇ»Å͵éÀ» À§ÇÑ ÀÎÅÍ³Ý °ÔÀÌÆ®¿þÀÌ ¿ªÇÒÀ» ´ã´çÇÏ´Â ¼­¹öÀ̰í ISA ¼­¹ö´Â ±â¾÷¿ë ¹æÈ­º® ±â´É°ú °í¼º´ÉÀÇ À¥ ij½¬(cache) ±â´ÉÀ» Áö¿øÇÏ´Â ¼­¹öÀÌ´Ù. ÀÌ ¼­¹öµéÀº FTP, telnet, mail, news, Intent Relay Chat(IRC) µî°ú °°Àº Windows Sockets(Winsock)¿Í ȣȯµÇ´Â Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥µé°ú ¿¬µ¿µÈ´Ù. Proxy Server 2.0 ¿Í ISA server 2000 ´Â Firewall and Winsock Proxy(WSP) ¼­ºñ½º »óÀÇ °áÇÔÀ¸·Î ÀÎÇÏ¿© ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ¼­¹öÀÇ ¼­ºñ½º¸¦ ¹æÇØÇÏ°í Æ®·¡ÇÈ Ã³¸®¸¦ ÁߴܽÃų ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. Proxy server 2.0ÀÇ °æ¿ì, µðÆúÆ®·Î WSP ¼­ºñ½º°¡ µ¿ÀÛÇϸç ISA server 2000ÀÇ °æ¿ì´Â ¼­¹ö°¡ firewall ¶Ç´Â intergrated ¸ðµå·Î ¼³Ä¡ ½Ã¿¡¸¸ Firewall ¼­ºñ½º°¡ µ¿ÀÛÇÑ´Ù. ÀÌ ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡Àº ¿ø°ÝÁö °ø°ÝÀÚµéÀÌ ¼­¹öÀÇ 1745/UDP Æ÷Æ®¿¡ Àß Á¶ÀÛµÈ ÆÐŶÀ» Àü´ÞÇÒ ¶§ ¹ß»ýÇÏ°Ô µÇ´Â µ¥, ÀÌ·¯ÇÑ ÇàÀ§´Â ¼­¹ö¸¦ ¹«ÇÑ ·çÇÁ¿¡ ºü¶ß·Á CPU »ç¿ë·üÀ» 100% ¿¡ À̸£°Ô ÇÔÀ¸·Î½á Æ®·¡ÇÈ Ã³¸®¸¦ ¹æÇØÇÑ´Ù. ¼­¹ö°¡ Á¤»óÀûÀÎ µ¿ÀÛ»óÅ·Πº¹±¸µÇ±â À§Çؼ­´Â ÀçºÎÆÃÀÌ ÇÊ¿äÇÏ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://securitytracker.com/alerts/2003/Apr/1006534.html
http://www.microsoft.com/technet/security/bulletin/MS03-012.asp
http://www.securiteam.com/windowsntfocus/5MP0B009PE.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Proxy Server 2.0
Microsoft ISA Server 2000
ÇØ°áÃ¥ Microsoft »çÀÇ À¥ »çÀÌÆ®µé ÂüÁ¶ÇÏ¿© ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù.

Proxy Server 2.0 ÀÇ °æ¿ì:
1. ÆäÀÌÁö http://microsoft.com/downloads/details.aspx?FamilyId=C81688B7-20FB-45EB-BAFD-031A0D2923E6&displaylang=en ¸¦ ¿¬´Ù.
2. Proxy Server 2.0À» À§ÇÑ º¸¾È ÆÐÄ¡¸¦ ´Ù¿î¹Þ±â À§ÇØ "Download" ¸µÅ©¸¦ Ŭ¸¯ÇÑ´Ù.
3. ¼³Ä¡¸¦ ½ÃÀÛÇϱâ À§ÇØ ´Ù¿î¹ÞÀº ÆÄÀÏ 43512_enu_i386_zip.exe ¸¦ ½ÇÇàÇÑ´Ù.
4. ¼³Ä¡ ¿Ï·á¸¦ À§Çؼ­ ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÑ´Ù.

ISA Server 2000ÀÇ °æ¿ì:
1. ÆäÀÌÁö http://microsoft.com/downloads/details.aspx?FamilyId=3C43FAD2-A888-4603-84B7-1053C8663436&displaylang=en ¸¦ ¿¬´Ù.
2. Proxy Server 2.0À» À§ÇÑ º¸¾È ÆÐÄ¡¸¦ ´Ù¿î¹Þ±â À§ÇØ "Download" ¸µÅ©¸¦ Ŭ¸¯ÇÑ´Ù.
3. ¼³Ä¡¸¦ ½ÃÀÛÇϱâ À§ÇØ ´Ù¿î¹ÞÀº ÆÄÀÏ isahf257.exe ¸¦ ½ÇÇàÇÑ´Ù.
°ü·Ã URL CVE-2003-0110 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL 11752 (ISS)