Ãë¾àÁ¡ID |
29043 |
À§Çèµµ |
40 |
Æ÷Æ® |
161 |
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
CISCO |
»ó¼¼¼³¸í |
ÇØ´ç Cisco IOS´Â OSPF Neighbor ÆÐŶ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡(Cisco ¹ö±× ID CSCdp58462)À» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ´Ù·®ÀÇ OSPF (Open Shortest Path First) neighbor ÆÐŶµéÀ» º¸³¾ ¶§ ¹ß»ýÇÑ´Ù. Ãë¾àÇÑ ¶ó¿ìÅÍ·Î 255°³ ÀÌ»óÀÇ OSPF neighbor ÆÐŶµéÀ» º¸³¿À¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖÀ¸¸ç Ãë¾àÇÑ ¹öÀüÀÇ ¼ÒÇÁÆ®¿þ¾î°¡ ÀÛµ¿ÁßÀÎ Àåºñ»ó¿¡ ¾ÇÀÇÀûÀÎ ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ´Â Á¤Ã¥ ÆíÁý±â¿¡¼ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/archive/1/312510 http://www.securityfocus.com/archive/1/312802 http://www.cisco.com/warp/public/707/cisco-sn-20030221-ospf.shtml http://archives.neohapsis.com/archives/bugtraq/2003-02/0239.html http://archives.neohapsis.com/archives/bugtraq/2003-02/0267.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Cisco IOS 11.2.x¿¡¼ 12.0.x |
ÇØ°áÃ¥ |
¾Æ·¡¿¡ ÀÖ´Â ¹®Á¦°¡ ÇØ°áµÈ Cisco IOS ¹öÀü ÁßÀÇ Çϳª·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÀÌ ¾÷±×·¹À̵åµéÀº CiscoÀÇ À¥ »çÀÌÆ®ÀÎ http://www.cisco.com/tacpage/sw-center/ ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù: 12.0(19)S ÀÌ»ó 12.0(19)ST ÀÌ»ó 12.1(1) ÀÌ»ó 12.1(1)DB ÀÌ»ó 12.1(1)DC ÀÌ»ó 12.1(1)T ÀÌ»ó
Àӽà Á¶Ä¡¹æ¹ýµé: OSPF MD5 ÀÎÁõÀ» ¼³Á¤ÇÏ´Â °ÍÀÌ´Ù. À̰ÍÀº ÀÎÅÍÆäÀ̽º ´ç ȤÀº ¿µ¿ª(area) ´çÀ¸·Î ÇàÇØ Áú ¼ö ÀÖ´Ù. ÀÚ¼¼ÇÑ Á¤º¸´Â ´ÙÀ½ MD5 ÀÎÁõ ¼³Á¤¿¡ °üÇÑ ¹®¼¸¦ Âü°íÇÏ¿©¾ß ÇÑ´Ù: http://www.cisco.com/en/US/tech/tk365/technologies_configuration_example09186a0080094069.shtml
¶Ç´Ù¸¥ °¡´ÉÇÑ Á¶Ä¡¹æ¹ýÀ¸·Î´Â ¾Æ·¡ÀÇ ¿¹¿Í °Í°ú °°ÀÌ Æ¯Á¤ OSPF neighborµé¸¸ ¸í½ÃÀûÀ¸·Î ÀÎÀÔ Á¢±Ù¸ñ·Ï(inbound access list)¿¡ Àû¿ëÇÏ´Â °ÍÀÌ´Ù:
access-list 100 permit ospf host a.b.c.x host 224.0.0.5 access-list 100 permit ospf host a.b.c.x host interface_ip access-list 100 permit ospf host a.b.c.y host 224.0.0.5 access-list 100 permit ospf host a.b.c.y host interface_ip access-list 100 permit ospf host a.b.c.z host 224.0.0.5 access-list 100 permit ospf host a.b.c.z host interface_ip access-list 100 permit ospf any host 224.0.0.6 access-list 100 deny ospf any any access-list 100 permit ip any any |
°ü·Ã URL |
CVE-2003-0100 (CVE) |
°ü·Ã URL |
6895 (SecurityFocus) |
°ü·Ã URL |
11373 (ISS) |
|