English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 11005
À§Çèµµ 30
Æ÷Æ® 37
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù DOS
»ó¼¼¼³¸í inetd µ¥¸óÀÌ °£´ÜÇÑ ¸î°³ÀÇ UDP¼­ºñ½º(echo, time, chargen, daytime) ¿äû¿¡ ´ëÇØ Source Port¸¦ üũÇÏÁö ¾ÊÀ» ¶§ ¹ß»ýÇÏ´Â ¹®Á¦·Î

¨ç Ping-PongÀ̶ó´Â DoS °ø°ÝÀ» ¹ÞÀ» ¼ö ÀÖ´Ù.
Attack ¼­¹ö¿¡¼­ µÎ°³ÀÇ Èñ»ý¼­¹ö¸¦ ¼³Á¤ÇØ µÎ°í Èñ»ý ¼­¹ö°£¿¡ µ¥ÀÌŸ°¡ ¿À°í°¡°Ô²û À§ÀÇ UDP Port·Î Spoof PacketÀ» º¸³½´Ù. ±×·¯¸é A Èñ»ý¼­¹ö¿¡¼­ º¸³»Áø ÀÀ´äÀÌ B Èñ»ý¼­¹ö·ÎÀÇ ¿äûÀ¸·Î µé¾î°¡°í B Èñ»ý¼­¹öÀÇ ÀÀ´äÀÌ A ¼­¹ö¿¡ ´ëÇÑ »õ·Î¿î ¿äûÀ¸·Î µÇ¾î ±× ´ÙÀ½ºÎÅÍ´Â µÎ Èñ»ý¼­¹öÀÇ UDP port°£¿¡ ÀÚµ¿ÀûÀ¸·Î ÆÐŶÀ» ÁÖ°í ¹Þ°Ô µÈ´Ù. °á±¹ ³×Æ®¿öÅ©ÀÇ ¼º´É¿¡ µû¶ó ¾öû³­ ¾çÀÇ TrafficÀÌ ¹ß»ýÇÏ¿© µÎ Èñ»ý¼­¹ö´Â DoS °ø°ÝÀ» ´çÇÏ°Ô µÈ´Ù.

¨è UDP bomb °ø°ÝÀ» ¹ÞÀ» ¼ö ÀÖ´Ù.
ÇØ´ç UDP port·Î SYN PacketÀ» º¸³» inetd¸¦ crash½ÃÄÑ °á±¹ NetworkÀ» ¸¶ºñ½ÃŲ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/36.php
ÇØ°áÃ¥ UNIX ½Ã½ºÅÛ:

1. /etc/inetd.conf ÆÄÀÏ¿¡ ÀÖ´Â time ¿£Æ®¸®¸¦ ÁÖ¼®Ã³¸® ÇÑ´Ù.
2. ´ÙÀ½ ¸í·É°ú °°ÀÌÇÏ¿© inetd ÇÁ·Î¼¼½º¿¡°Ô ¼öÁ¤µÈ ³»¿ëÀ» ÀÐ¾î µéÀ̵µ·Ï ÇÑ´Ù:
kill -HUP <inetd process id>

*Solaris 10, Solaris 11ÀÇ °æ¿ì:
svcadm disable svc:/network/time:dgram
svcadm disable svc:/network/time:stream

*Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
/etc/xinetd.d/time-dgram ¹× /etc/xinetd.d/time-streamÀ» ¿­¾î disable=yes·Î ¼³Á¤ÇÑ ÈÄ xinetd¸¦ Àç½ÃÀÛÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)