English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 11006
À§Çèµµ 30
Æ÷Æ® 19
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù DOS
»ó¼¼¼³¸í inetd µ¥¸óÀÌ °£´ÜÇÑ ¸î°³ÀÇ UDP¼­ºñ½º(echo, time, chargen, daytime) ¿äû¿¡ ´ëÇØ Source Port¸¦ üũÇÏÁö ¾ÊÀ» ¶§ ¹ß»ýÇÏ´Â ¹®Á¦·Î

¨ç Ping-PongÀ̶ó´Â DoS °ø°ÝÀ» ¹ÞÀ» ¼ö ÀÖ´Ù.
Attack ¼­¹ö¿¡¼­ µÎ°³ÀÇ Èñ»ý¼­¹ö¸¦ ¼³Á¤ÇØ µÎ°í Èñ»ý ¼­¹ö°£¿¡ µ¥ÀÌŸ°¡ ¿À°í°¡°Ô²û À§ÀÇ UDP Port·Î Spoof PacketÀ» º¸³½´Ù. ±×·¯¸é A Èñ»ý¼­¹ö¿¡¼­ º¸³»Áø ÀÀ´äÀÌ B Èñ»ý¼­¹ö·ÎÀÇ ¿äûÀ¸·Î µé¾î°¡°í B Èñ»ý¼­¹öÀÇ ÀÀ´äÀÌ A ¼­¹ö¿¡ ´ëÇÑ »õ·Î¿î ¿äûÀ¸·Î µÇ¾î ±× ´ÙÀ½ºÎÅÍ´Â µÎ Èñ»ý¼­¹öÀÇ UDP port°£¿¡ ÀÚµ¿ÀûÀ¸·Î ÆÐŶÀ» ÁÖ°í ¹Þ°Ô µÈ´Ù. °á±¹ ³×Æ®¿öÅ©ÀÇ ¼º´É¿¡ µû¶ó ¾öû³­ ¾çÀÇ TrafficÀÌ ¹ß»ýÇÏ¿© µÎ Èñ»ý¼­¹ö´Â DoS °ø°ÝÀ» ´çÇÏ°Ô µÈ´Ù.

¨è UDP bomb °ø°ÝÀ» ¹ÞÀ» ¼ö ÀÖ´Ù.
ÇØ´ç UDP port·Î SYN PacketÀ» º¸³» inetd¸¦ crash½ÃÄÑ °á±¹ NetworkÀ» ¸¶ºñ½ÃŲ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/36.php
http://online.securityfocus.com/archive/1/6407

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Any version
Linux Any version
ÇØ°áÃ¥ ´ÙÀ½°ú °°Àº ÀýÂ÷¿¡ ÀÇÇØ chargen ¼­ºñ½º¸¦ ÀÛµ¿ÁßÁö½Ã±æ °ÍÀ» ±Ç°íÇÑ´Ù:

UNIX ½Ã½ºÅÛ:

1. /etc/inetd.conf ÆÄÀÏ¿¡ ÀÖ´Â chargen ¿£Æ®¸®¸¦ ÁÖ¼®Ã³¸® ÇÑ´Ù.
2. ´ÙÀ½ ¸í·É°ú °°ÀÌÇÏ¿© inetd ÇÁ·Î¼¼½º¿¡°Ô ¼öÁ¤µÈ ³»¿ëÀ» ÀÐ¾î µéÀ̵µ·Ï ÇÑ´Ù:
kill -HUP <inetd process id>

*Solaris 10, Solaris 11ÀÇ °æ¿ì:
svcadm disable svc:/network/chargen:dgram
svcadm disable svc:/network/chargen:stream

*Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
/etc/xinetd.d/chargen-dgram ¹× /etc/xinetd.d/chargen-streamÀ» ¿­¾î disable=yes·Î ¼³Á¤ÇÑ ÈÄ xinetd¸¦ Àç½ÃÀÛÇÑ´Ù.

À©µµ¿ì NT/2000 ½Ã½ºÅÛ:

Chargen ¼­ºñ½º¸¸À» ÀÛµ¿ÁßÁö ½ÃŰ±æ ¿øÇÑ´Ù¸é:
1. ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ¿ÀÇÂÇÏ¿© À©µµ¿ì NT/2000 ½ÃÀÛ ¸Þ´º·ÎºÎÅÍ '½ÇÇà'À» ¼±ÅÃÇÑ ÈÄ, regedt32 ¸¦ ŸÀÌÇÎÇϰí 'È®ÀÎ'À» Ŭ¸¯ÇÑ´Ù.
2. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SimpTcp\Parameters ۸¦ ¼±ÅÃÇÑ´Ù.
3. EnableTcpChargen ¿Í EnableUdpChargen ¸¦ 0À¸·Î ¼³Á¤ÇÑ´Ù.
4. º¯µ¿»çÇ×À» Àû¿ëÇϱâ À§ÇØ 'Simple TCP/IP service'¸¦ Àç½ÃÀÛ½ÃŲ´Ù.

* Windows XP, 2003, VISTA, 7, 2008, 8, 2012, 10, 2016, 2019
1. ½ÇÇàâ(Win Key + R)¿¡¼­ regedit32¸¦ ½ÇÇàÇÑ´Ù.
2. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SimpTcp\Parameters ۸¦ ¼±ÅÃÇÑ´Ù.
3. EnableTcpChargen ¿Í EnableUdpChargen ¸¦ 0À¸·Î ¼³Á¤ÇÑ´Ù.
4. º¯µ¿»çÇ×À» Àû¿ëÇϱâ À§ÇØ 'Simple TCP/IP service'¸¦ Àç½ÃÀÛ½ÃŲ´Ù.
°ü·Ã URL CVE-1999-0103 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)