English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29040
À§Çèµµ 40
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç Cisco IOS´Â ºñÁ¤»óÀûÀÎ SIP ÆÐŶµéÀ» ÅëÇÑ ¼­ºñ½º°ÅºÎ Ãë¾àÁ¡(CISCO ¹ö±× ID CSCdz39284¿Í CSCdz41124)À» °¡Áö°í ÀÖ´Ù.
Oulu ´ëÇб³ º¸¾È ÇÁ·Î±×·¡¹Ö ±×·ìÀº SIP (Session Initiation Protocol) ±¸Çöµé¿¡¼­ ¸¹Àº Ãë¾àÁ¡µéÀ» ¹ß°ßÇß´Ù. ÀÌ ¹®Á¦µéÀº ÇÁ·ÎÅäÄÝÀ» ±¸ÇöÇÑ Àåºñµé¿¡¼­ ¼­ºñ½º°ÅºÎ¸¦ À¯¹ßÇÏ´Â µ¥¿¡ µµ¿ëµÉ ¼ö ÀÖ´Ù. ¶ÇÇÑ ¾î¶² ƯÁ¤ Á¶°Çµé¿¡¼­´Â Àåºñµé¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º°¡ °¡´ÉÇÑ °ÍÀ¸·Î ¾Ë·ÁÁ® ÀÖ´Ù.

SIP´Â IP¸¦ ÅëÇÑ ¸ÖƼ¹Ìµð¾î ȸÀǸ¦ À§ÇÑ Internet Engineering Task Force (IETF) Ç¥ÁØÀÌ´Ù. SIP´Â µÎ°³ ÀÌ»óÀÇ Á¾´Ü°£¿¡ È£Ãâ(call)µéÀ» ¸Î°Å³ª, À¯ÁöÇϰųª, Á¾·áÇÏ´Â µ¥¿¡ »ç¿ëµÉ ¼ö ÀÖ´Â (RFC 2543°ú 3261¿¡ Á¤ÀǵÈ) ASCII ±â¹Ý, ¾îÇø®ÄÉÀÌ¼Ç °èÃþÀÇ Á¦¾î ÇÁ·ÎÅäÄÝÀÌ´Ù.

12.2T train ȤÀº 12.2 'X' trainµéÀÇ Cisco IOS ¹öÀüµéÀÌ °¡µ¿µÇ´Â ÀåºñµéÀº SIP ÇʵåµéÀÇ ºÎÀûÀýÇÑ Ã³¸®·Î ÀÎÇØ ¸®ºÎÆÃ(reset) µÉ ¼ö ÀÖ´Ù. ÀÌ Ãë¾àÁ¡µéÀº Cisco ¹ö±× ID CSCdz39284¿Í CSCdz41124¿¡ ¹®¼­È­µÇ¾î ÀÖ´Ù. CSCdz39284¿¡ Ãë¾àÇÑ Á¶°ÇÀ¸·Î´Â Àåºñ¿¡ Ãë¾àÇÑ ¹öÀüÀÇ IOS ¹öÀüÀÌ °¡µ¿ÁßÀ̸鼭 SIP °ÔÀÌÆ®¿þÀ̷μ­ ¼³Á¤µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù. ¶ÇÇÑ NAT¸¦ ¼öÇàÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Â Ãë¾àÇÑ ¹öÀüÀÇ Cisco IOS°¡ °¡µ¿µÇ´Â ÀåºñµéÀÌ SIP°¡ Àü¼ÛÀ» À§ÇØ UDP¸¦ »ç¿ëÇÑ´Ù¸é CSCdz41124¿¡ Ãë¾àÇÏ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿­À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ­´Â Á¤Ã¥ ÆíÁý±â¿¡¼­ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿­À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml
http://www.cert.org/advisories/CA-2003-06.html
http://www.kb.cert.org/vuls/id/528719
http://www.ee.oulu.fi/research/ouspg/protos/testing/c07/sip/
http://www.securitytracker.com/alerts/2003/Feb/1006167.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Cisco IOS 12.2T
Cisco IOS 12.2X
ÇØ°áÃ¥ ´ÙÀ½ Cisco º¸¾È ±Ç°í¾ÈÀ» ÂüÁ¶ÇÏ¿© Cisco IOSÀÇ °¡Àå ÃֽйöÀü (12.2(11)T3 ȤÀº 12.2(13)T1 ÀÌ»ó)À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cisco.com/warp/public/707/cisco-sa-20030221-protos.shtml
ÀÌ ¾÷±×·¹À̵åµéÀº CiscoÀÇ À¥ »çÀÌÆ®ÀÎ http://www.cisco.com/tacpage/sw-center/ ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â ¸¸¾à SIP ÇÁ·ÎÅäÄÝÀ» À§ÇØ NAT°¡ ÇÊ¿äÇÏÁö ¾ÊÀ¸¸é, ÀϹÝÀûÀÎ NAT ¼­ºñ½ºµéÀ» ¼öÇàÇϵµ·Ï ¼³Á¤µÇ¾î ÀÖ´Â Cisco IOSÀÇ Ãë¾àÇÑ ¹öÀüµéÀ» °¡µ¿ÁßÀÎ ÀåºñµéÀº 5060ÀÇ Ãâ¹ßÁö ȤÀº ¸ñÀûÁö Æ÷Æ®µéÀ» ¾²´Â UDP Æ®·¡ÇÈÀ» Â÷´ÜÇÔÀ¸·Î½á SIP Æ®·¡ÇÈÀÌ NAT º¯È¯ÀÌ µÇÁö ¾Êµµ·Ï ÇØ ÁÖ´Â Á¢±Ù¸ñ·Ï(Access List)À» °£´ÜÇÏ°Ô ±¸ÇöÇÒ ¼ö ÀÖ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL 6904 (SecurityFocus)
°ü·Ã URL 11379 (ISS)