English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29062
À§Çèµµ 40
Æ÷Æ® 161
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç Cisco IOS Firewall Feature SetÀº ACL ¿ìȸ Ãë¾àÁ¡(CISCO ¹ö±× ID CSCdv48261)À» °¡Áö°í ÀÖ´Ù. Á¤È®ÇÑ ¼¼¼Ç ÀμöµéÀ» »ç¿ëÇÏ¿© ÀÌ Ãë¾àÁ¡À» ¼º°øÀûÀ¸·Î µµ¿ëÇϸé, Àΰ¡µÈ ³×Æ®¿öÅ©(trusted network)¿¡ ÀÇÇØ¼­¸¸ ¾×¼¼½º °¡´ÉÇÑ ÇÁ·Î¼¼½ºµé¿¡°Ô ÀÓÀÇÀÇ µ¥ÀÌÅ͸¦ Àü´ÞÇÒ ¼ö ÀÖ´Ù. ÃÖ¾ÇÀÇ °æ¿ì, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â µ¿Àû ¾×¼¼½º ¸ñ·Ï(dynamic access list)À» ¿ìȸ(bypass)ÇÏ°í º¸È£¹Þ´Â ³×Æ®¿öÅ©(protected network) »óÀÇ È£½ºÆ®¿¡ ½Ö¹æÇâ(interactive) ¼¼¼ÇÀ» ¸Î°Ô ÇØ ÁÙ ¼öµµ ÀÖ´Ù.
IOS ¹öÀü 11.2P¿¡¼­ µîÀåÇÑ IOS Firewall Feature setÀº Cisco ÅëÇÕ º¸¾È ¼ÒÇÁÆ®¿þ¾î(Secure Integrated Software), ȤÀº CBAC(Context Based Access Control)·Î ¾Ë·ÁÁø IP ±â¹ÝÀÇ Stateful Inspection ½Ã½ºÅÛÀÌ´Ù. CBAC´Â º¸È£¹Þ´Â ³×Æ®¿öÅ©·ÎºÎÅÍ ¾î¶² ¼¼¼ÇÀÌ ½ÃÀÛµÉ ¶§ ±× ¼¼¼Ç¿¡ ´ëÇÑ ÀÀ´ä Æ®·¡ÇÈ(return traffic)ÀÇ Çã¿ëÀ» À§ÇØ µ¿Àû ¾×¼¼½º ¸ñ·Ï¿¡ »õ·Î¿î ¿£Æ®¸®¸¦ »ý¼ºÇÑ´Ù. ±×·¯³ª, µ¿Àû ¾×¼¼½º ¸ñ·Ï¿¡¼­ ÀÀ´ä Æ®·¡ÇÈÀ» °Ë»çÇÒ ¶§, ÆÐŶÀÇ ¹ß½ÅÁö/¸ñÀûÁö ÁÖ¼Ò¿Í Æ÷Æ®µéÀº °Ë»çµÇÁö¸¸ IP ÇÁ·ÎÅäÄÝ Å¸ÀÔÀº °Ë»çµÇÁö ¾Ê´Â´Ù. À̰ÍÀº µ¿Àû ¾×¼¼½º ¸ñ·Ï¿¡ ÀÇÇØ °ÅºÎµÇ¾îÁ®¾ß ÇÒ ´Ù¸¥ ÇÁ·ÎÅäÄÝ Å¸ÀÔÀÇ ÆÐŶÀ» º¸È£¹Þ´Â ³×Æ®¿öÅ©·Î Çã¿ëÇØ ÁÙ ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ÇØ´ç ½Ã½ºÅÛÀÇ ¹öÀüÁ¤º¸¸¸À» È®ÀÎÇÑ´Ù. µû¶ó¼­ °ÅÁþ ¾ç¼º¹ÝÀÀ(False Positive)À» º¸ÀÏ ¼ö ÀÖ´Ù. ÀÌ Á¡°ËÇ׸ñÀº ¶ÇÇÑ ¹öÀüÁ¤º¸¸¦ ¼öÁýÇϱâ À§ÇÏ¿© Àб⠱ÇÇÑÀÇ SNMP Community ¹®ÀÚ¿­À» ÇÊ¿ä·Î ÇÑ´Ù. À̸¦ À§Çؼ­´Â Á¤Ã¥ ÆíÁý±â¿¡¼­ Á¡°ËÇ׸ñ "snmp/guessable/r"¿¡ Ÿ´çÇÑ Community ¹®ÀÚ¿­À» Ãß°¡ÇÏ¿©¾ß ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml
http://www.cisco.com/univercd/cc/td/doc/product/software/ios113ed/113t/113t_3/firewall.htm
http://www.kb.cert.org/vuls/id/362483

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CISCO IOS 11.2P
CISCO IOS 11.3T
CISCO IOS 12.0, 12.0T
CISCO IOS 12.1, 12.1T, 12.1E
CISCO IOS 12.2, 12.2T
CISCO ¶ó¿ìÅÍ ½Ã¸®Áî : 800, 820, 950, 1400, 1600, 1700, 2500, 2600, 3600, 4000 °ÔÀÌÆ®¿þÀÌ, 4224, 7100, 7200, 7400, 7500, SOHO 70, ubr900, ICS7750
CISCO IOS ¼ÒÇÁÆ®¿þ¾î°¡ žÀçµÈ Catalyst 5000¿Í 6000
ÇØ°áÃ¥ ´ÙÀ½ Cisco º¸¾È ±Ç°í¾ÈÀÇ "Software Versions and Fixes"¸¦ ÂüÁ¶ÇÏ¿© ¹®Á¦°¡ ÇØ°áµÈ Cisco IOS ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cisco.com/warp/public/707/IOS-cbac-dynacl-pub.shtml

¾÷±×·¹À̵åµéÀº Cisco À¥ »çÀÌÆ®ÀÎ http://www.cisco.com ¿¡ ÀÖ´Â Software Center¸¦ ÅëÇØ ±¸ÇÒ ¼ö ÀÖ´Ù.
°ü·Ã URL CVE-2001-0929 (CVE)
°ü·Ã URL 3588 (SecurityFocus)
°ü·Ã URL 7614 (ISS)