English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29043
À§Çèµµ 40
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç Cisco IOS´Â OSPF Neighbor ÆÐŶ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡(Cisco ¹ö±× ID CSCdp58462)À» °¡Áö°í ÀÖ´Ù. ÀÌ Ãë¾àÁ¡Àº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ´Ù·®ÀÇ OSPF (Open Shortest Path First) neighbor ÆÐŶµéÀ» º¸³¾ ¶§ ¹ß»ýÇÑ´Ù. Ãë¾àÇÑ ¶ó¿ìÅÍ·Î 255°³ ÀÌ»óÀÇ OSPF neighbor ÆÐŶµéÀ» º¸³¿À¸·Î½á ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ¹öÆÛ¸¦ ¿À¹öÇÃ·Î¿ì ½Ãų ¼ö ÀÖÀ¸¸ç Ãë¾àÇÑ ¹öÀüÀÇ ¼ÒÇÁÆ®¿þ¾î°¡ ÀÛµ¿ÁßÀÎ Àåºñ»ó¿¡ ¾ÇÀÇÀûÀÎ ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿­À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ­´Â Á¤Ã¥ ÆíÁý±â¿¡¼­ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿­À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/archive/1/312510
http://www.securityfocus.com/archive/1/312802
http://www.cisco.com/warp/public/707/cisco-sn-20030221-ospf.shtml
http://archives.neohapsis.com/archives/bugtraq/2003-02/0239.html
http://archives.neohapsis.com/archives/bugtraq/2003-02/0267.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Cisco IOS 11.2.x¿¡¼­ 12.0.x
ÇØ°áÃ¥ ¾Æ·¡¿¡ ÀÖ´Â ¹®Á¦°¡ ÇØ°áµÈ Cisco IOS ¹öÀü ÁßÀÇ Çϳª·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. ÀÌ ¾÷±×·¹À̵åµéÀº CiscoÀÇ À¥ »çÀÌÆ®ÀÎ http://www.cisco.com/tacpage/sw-center/ ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù:
12.0(19)S ÀÌ»ó
12.0(19)ST ÀÌ»ó
12.1(1) ÀÌ»ó
12.1(1)DB ÀÌ»ó
12.1(1)DC ÀÌ»ó
12.1(1)T ÀÌ»ó

Àӽà Á¶Ä¡¹æ¹ýµé:
OSPF MD5 ÀÎÁõÀ» ¼³Á¤ÇÏ´Â °ÍÀÌ´Ù. À̰ÍÀº ÀÎÅÍÆäÀ̽º ´ç ȤÀº ¿µ¿ª(area) ´çÀ¸·Î ÇàÇØ Áú ¼ö ÀÖ´Ù. ÀÚ¼¼ÇÑ Á¤º¸´Â ´ÙÀ½ MD5 ÀÎÁõ ¼³Á¤¿¡ °üÇÑ ¹®¼­¸¦ Âü°íÇÏ¿©¾ß ÇÑ´Ù:
http://www.cisco.com/en/US/tech/tk365/technologies_configuration_example09186a0080094069.shtml

¶Ç´Ù¸¥ °¡´ÉÇÑ Á¶Ä¡¹æ¹ýÀ¸·Î´Â ¾Æ·¡ÀÇ ¿¹¿Í °Í°ú °°ÀÌ Æ¯Á¤ OSPF neighborµé¸¸ ¸í½ÃÀûÀ¸·Î ÀÎÀÔ Á¢±Ù¸ñ·Ï(inbound access list)¿¡ Àû¿ëÇÏ´Â °ÍÀÌ´Ù:

access-list 100 permit ospf host a.b.c.x host 224.0.0.5
access-list 100 permit ospf host a.b.c.x host interface_ip
access-list 100 permit ospf host a.b.c.y host 224.0.0.5
access-list 100 permit ospf host a.b.c.y host interface_ip
access-list 100 permit ospf host a.b.c.z host 224.0.0.5
access-list 100 permit ospf host a.b.c.z host interface_ip
access-list 100 permit ospf any host 224.0.0.6
access-list 100 deny ospf any any
access-list 100 permit ip any any
°ü·Ã URL CVE-2003-0100 (CVE)
°ü·Ã URL 6895 (SecurityFocus)
°ü·Ã URL 11373 (ISS)