English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29060
À§Çèµµ 40
Æ÷Æ® 5009
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù WAP
»ó¼¼¼³¸í ÇØ´ç Airport ¹«¼± Access Point´Â °ü¸® Æ÷Æ®¸¦ ÅëÇØ ÀÎÁõ Á¤º¸µéÀ» ³ëÃâÇÑ´Ù.
Apple »çÀÇ AirPort Àåºñ´Â ³×Æ®¿öÅ© Ŭ¶óÀÌ¾ðÆ®µé¿¡°Ô 802.11 ¼­ºñ½º¸¦ Á¦°øÇØ ÁÖ´Â ¹«¼± Access PointÀÌ´Ù. ÀÌ Àåºñ´Â TCP Æ÷Æ®(5009/tcp)¸¦ ÅëÇØ ÀÚ»çÀÇ °ü¸® ÇÁ·ÎÅäÄÝÀ» ÀÌ¿ëÇÏ¿© °ü¸®µÈ´Ù. °ü¸® ±â´ÉÀº ÀÎÁõ ½Å¿ëÁ¤º¸µéÀ» º¸È£ÇÏ´Â µ¥¿¡ ÀÖ¾î ³Ê¹« °£´ÜÇÑ ¾ÏÈ£¹æ½Ä(°íÁ¤ Ű·Î XOR)À» »ç¿ëÇϰí ÀÖ´Ù. ¸¸¾à AirPort°¡ Ethernet ÀÎÅÍÆäÀ̽º¸¦ ÅëÇØ ȤÀº ¾ÈÀüÇÏÁö ¾ÊÀº (non-WEP) ¹«¼± Á¢¼ÓÀ» °æÀ¯ÇÏ¿© °ü¸®µÈ´Ù¸é, °ø°ÝÀÚ°¡ ³×Æ®¿öÅ©¸¦ µµÃ»ÇÏ¿© AirPort·Î °ü¸® ±ÇÇÑÀ» °¡Áö´Â ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/securitynews/5NP0H2AA0I.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Apple AirPort Wireless Access Point
ÇØ°áÃ¥ 2014³â 4¿ù ÇöÀç ÆÐÄ¡³ª ¾÷±×·¹À̵å´Â ³ª¿Í ÀÖÁö ¾Ê´Ù.

Àӽà Á¶Ä¡¹æ¹ýµé:

À¯¼± Á¢¼ÓÀ̳ª WEP ±â¹ÝÀÇ ¹«¼± Á¢¼ÓÀ» ÅëÇØ¼­ AirPort Base StationÀ» °ü¸®Çϵµ·Ï ÇÏ¿©¾ß ÇÑ´Ù.

AirPort Base StationÀ» ¾ÈÀüÇÏ°Ô °ü¸®ÇÒ ¼ö ÀÖ´Â À¯ÀÏÇÑ ¹æ¹ýÀº Cross Ethernet ÄÉÀ̺íÀ» ÅëÇØ °ü¸®ÀûÀÎ Á¢¼ÓÀ» ÇÏ´Â °ÍÀÌ´Ù. ȯ°æÀûÀÎ Á¦¾àÀ¸·Î ÀÎÇØ À̰ÍÀÌ ¾î·Æ´Ù¸é ¹«¼± ³×Æ®¿öÅ©°¡ ¾Æ´Ñ, Ethernet ³×Æ®¿öÅ©¸¦ ÅëÇØ¼­¸¸ AirPort Base StationÀÌ °ü¸®µÇµµ·Ï ÇØ¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2003-0270 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)