English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29059
À§Çèµµ 40
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç Cisco IOS´Â SSH ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡µé(CISCO Bug ID CSCdz60229, CSCdy87221, CSCdu75477)À» °¡Áö°í ÀÖ´Ù.
ÀÌ Ãë¾àÁ¡µéÀº ¸î °¡ÁöÀÇ ¹öÆÛ ¿À¹öÇ÷οìµé¿¡ ±âÀÎÇϸç Ãë¾àÇÑ Àåºñ¿¡ ´ëÇØ Àç½ÃÀÛ(reload)À» À¯¹ß½Ãų ¼ö ÀÖ´Ù. Àç½ÃÀÛÇÏ´Â ¸î ºÐ µ¿¾È ÀåºñÀÇ »ç¿ëÀ» ÁߴܽÃŲ´Ù. Àç½ÃÀÛ ÈÄ Á¤»óÀûÀÎ »óÅ·ΠÀåºñ°¡ º¹±¸µÈ »óÅ¿¡¼­µµ ¿©ÀüÈ÷ Ãë¾àÇϸç, ¶ÇÇÑ ¹Ýº¹ÀûÀ¸·Î Àç½ÃÀÛ(reload)µÉ ¼ö ÀÖ´Ù. Rapid7 »ç¿¡¼­´Â SSH (Secure Shell) ÇÁ·ÎÅäÄÝÀÇ ±¸Çöµé¿¡ ´ëÇÑ Å×½ºÆ® ¸ñÀûÀ¸·Î ÇÑ ¹úÀÇ Á¶ÀÛµÈ ÆÐŶµéÀ» Á¦ÀÛÇØ ³õ¾Ò´Ù. ¸¸¾à SSH ¼­¹ö°¡ ÀÛµ¿µÇ°í ÀÖ´Ù¸é, ¸î °³ÀÇ Å×½ºÆ® ÆÐŶµé ¸¸À¸·Îµµ ÀÎÁõ ÇÁ·Î¼¼½º°¡ ºÒ·ÁÁö±â Àü ÀåºñÀÇ °­Á¦ÀûÀÎ Àç½ÃÀÛÀ» À¯¹ßÇÒ ¼ö ÀÖ´Ù. Á¶ÀÛµÈ ÆÐŶÀ¸·Î Ãë¾àÇÑ Cisco Àåºñ¿¡ ´ëÇÑ SSH Á¢¼Ó ½Ãµµ°¡ ÀÌ·ç¾îÁú ¶§¸¶´Ù Àåºñ´Â ½Ã½ºÅÛ Á¤Áö(hang)³ª ¸®ºÎÆÃÀ» ÀÏÀ¸Å²´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿­À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ­´Â Á¤Ã¥ ÆíÁý±â¿¡¼­ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿­À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cisco.com/warp/public/707/ssh-packet-suite-vuln.shtml
http://www.cert.org/advisories/CA-2002-36.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Cisco IOS releases 12.0S, 12.0ST, 12.1T, 12.1E, 12.2, 12.2T, 12.2S
ÇØ°áÃ¥ ´ÙÀ½ Cisco º¸¾È ±Ç°í¾È (SSH Malformed Packet Vulnerabilities)ÀÇ "Software Versions and Fixes" À» ÂüÁ¶ÇÏ¿© ¹®Á¦°¡ ÇØ°áµÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cisco.com/warp/public/707/ssh-packet-suite-vuln.shtml

¾÷±×·¹À̵åµéÀº Cisco À¥ »çÀÌÆ®ÀÎ http://www.cisco.com/tacpage/sw-center/ ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.

Àӽà Á¶Ä¡¹æ¹ýµé:

Cisco IOS SoftwareÀÇ °æ¿ì:
1. ¼³Á¤¸ðµå¿¡¼­ "crypto key zeroize rsa" ¸í·ÉÀ» »ç¿ëÇØ¼­ SSH ¼­ºñ½º¸¦ ÁßÁöÇÑ´Ù. RSA Ű ½ÖÀ» »ý¼ºÇÒ ¶§ SSH ¼­¹ö´Â ÀÚµ¿À¸·Î ÀÛµ¿ÇÏ°Ô µÈ´Ù. RSA ۸¦ "zeroing" ½ÃŰ´Â °ÍÀº SSH ¼­¹ö¸¦ ¿ÏÀüÈ÷ ÀÛµ¿ ÁßÁö½Ãų ¼ö ÀÖ´Â À¯ÀÏÇÑ ¹æ¹ýÀÌ´Ù.
2. ¼³Á¤ ¸ðµåÀÇ VTY(°¡»ó ÄܼÖ) ¶óÀÎ »ó¿¡¼­ Çã¿ëµÈ transport °èÃþ ¼­ºñ½ºµéÀÇ ¸®½ºÆ®·ÎºÎÅÍ 'ssh'ÀÌ Á¦°ÅµÈ "transport input" ¸í·ÉÀ» ÀçÀû¿ë, »ç¿ëÇÒ transport ÇÁ·ÎÅäÄÝ¿¡¼­ SSH¸¦ Á¦°ÅÇÑ´Ù. ¿¹¸¦ µé¾î,
line vty 0 4
transport input telnet
end
3. ´ÙÀ½À» Âü°íÇÏ¿© VTY »ó¿¡ ACL(Access Control List)¸¦ »ç¿ëÇÏ¿© Àΰ¡µÈ È£½ºÆ®¿ÍÀÇ ¿¬°á¸¸ Çã¿ëÇϰųª ¸ðµç SSH Æ®·¡ÇÈÀ» Â÷´ÜÇÑ´Ù.
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2950/1219ea1/scg/swacl.htm#xtocid14

* °æ°í: ÀÌ Àӽà Á¶Ä¡¹æ¹ýÀº Àåºñ ÀÎÁõÀ» À§ÇØ RSA Ű ½ÖÀ» »ç¿ëÇϰųª ±× RSA Ű ½Ö ±â¹ÝÀÇ Áõ¸í¼­¸¦ »ç¿ëÇÏ´Â Àåºñ¿¡¼­ Á¾·áµÇ´Â IPSEC ¼¼¼Ç¿¡ ¿¹ÃøÇÏÁö ¸øÇÑ ¿µÇâÀ» ¹ÌÄ¥ ¼ö ÀÖ´Ù.

Cisco Aironet SoftwareÀÇ °æ¿ì:
Cisco Aironet Access Point »ó¿¡ Á¸ÀçÇÏ´Â IP Æ÷Æ® ÇÊÅ͸µ ±â´ÉÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.
IP Æ÷Æ® ÇÊÅÍ ¼³Á¤¿¡ °üÇÑ Á¤º¸´Â ´ÙÀ½ÀÇ Access Point ¼³Á¤ °¡À̵带 Âü°íÇÑ´Ù.
http://www.cisco.com/univercd/cc/td/doc/product/wireless/airo_350/accsspts/ap350scg/ap350ch5.htm
¶ÇÇÑ, ¹æÈ­º®À̳ª ¶ó¿ìÅÍ¿Í °°Àº ¿ÜºÎ ÆÐŶ ÇÊÅ͸µ Àåºñ¸¦ »ç¿ëÇØ¼­ TCP Æ÷ºz 22»óÀÇ Æ®·¡ÇÈÀ» ÇÊÅ͸µÇÏ¿© µé¾î¿À´Â(inbound) SSH ¿¬°áÀ» Â÷´ÜÇÑ´Ù.

´õ ÀÚ¼¼ÇÑ ³»¿ëÀº ´ÙÀ½ »çÀÌÆ®¿¡¼­ º¼ ¼ö ÀÖ´Ù:
http://www.cisco.com/warp/public/707/ssh-packet-suite-vuln.shtml
°ü·Ã URL CVE-2002-1357,CVE-2002-1358,CVE-2002-1359,CVE-2002-1360 (CVE)
°ü·Ã URL 6397,6405,6407,6408,6410 (SecurityFocus)
°ü·Ã URL 10868,10869,10870,10871 (ISS)