| Ãë¾àÁ¡ID |
11005 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
37 |
| ÇÁ·ÎÅäÄÝ |
UDP |
| ºÐ·ù |
DOS |
| »ó¼¼¼³¸í |
inetd µ¥¸óÀÌ °£´ÜÇÑ ¸î°³ÀÇ UDP¼ºñ½º(echo, time, chargen, daytime) ¿äû¿¡ ´ëÇØ Source Port¸¦ üũÇÏÁö ¾ÊÀ» ¶§ ¹ß»ýÇÏ´Â ¹®Á¦·Î
¨ç Ping-PongÀ̶ó´Â DoS °ø°ÝÀ» ¹ÞÀ» ¼ö ÀÖ´Ù. Attack ¼¹ö¿¡¼ µÎ°³ÀÇ Èñ»ý¼¹ö¸¦ ¼³Á¤ÇØ µÎ°í Èñ»ý ¼¹ö°£¿¡ µ¥ÀÌŸ°¡ ¿À°í°¡°Ô²û À§ÀÇ UDP Port·Î Spoof PacketÀ» º¸³½´Ù. ±×·¯¸é A Èñ»ý¼¹ö¿¡¼ º¸³»Áø ÀÀ´äÀÌ B Èñ»ý¼¹ö·ÎÀÇ ¿äûÀ¸·Î µé¾î°¡°í B Èñ»ý¼¹öÀÇ ÀÀ´äÀÌ A ¼¹ö¿¡ ´ëÇÑ »õ·Î¿î ¿äûÀ¸·Î µÇ¾î ±× ´ÙÀ½ºÎÅÍ´Â µÎ Èñ»ý¼¹öÀÇ UDP port°£¿¡ ÀÚµ¿ÀûÀ¸·Î ÆÐŶÀ» ÁÖ°í ¹Þ°Ô µÈ´Ù. °á±¹ ³×Æ®¿öÅ©ÀÇ ¼º´É¿¡ µû¶ó ¾öû³ ¾çÀÇ TrafficÀÌ ¹ß»ýÇÏ¿© µÎ Èñ»ý¼¹ö´Â DoS °ø°ÝÀ» ´çÇÏ°Ô µÈ´Ù.
¨è UDP bomb °ø°ÝÀ» ¹ÞÀ» ¼ö ÀÖ´Ù. ÇØ´ç UDP port·Î SYN PacketÀ» º¸³» inetd¸¦ crash½ÃÄÑ °á±¹ NetworkÀ» ¸¶ºñ½ÃŲ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/36.php |
| ÇØ°áÃ¥ |
UNIX ½Ã½ºÅÛ:
1. /etc/inetd.conf ÆÄÀÏ¿¡ ÀÖ´Â time ¿£Æ®¸®¸¦ ÁÖ¼®Ã³¸® ÇÑ´Ù. 2. ´ÙÀ½ ¸í·É°ú °°ÀÌÇÏ¿© inetd ÇÁ·Î¼¼½º¿¡°Ô ¼öÁ¤µÈ ³»¿ëÀ» ÀÐ¾î µéÀ̵µ·Ï ÇÑ´Ù: kill -HUP <inetd process id>
*Solaris 10, Solaris 11ÀÇ °æ¿ì: svcadm disable svc:/network/time:dgram svcadm disable svc:/network/time:stream
*Enterprise Linux 6.4, CentOS 6.4, Fedora 19: /etc/xinetd.d/time-dgram ¹× /etc/xinetd.d/time-streamÀ» ¿¾î disable=yes·Î ¼³Á¤ÇÑ ÈÄ xinetd¸¦ Àç½ÃÀÛÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|