English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 11009
À§Çèµµ 30
Æ÷Æ® 9
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DOS
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛÀº Discard ¼­ºñ½º°¡ ±¸µ¿ÁßÀÌ´Ù. ÀÌ ¼­ºñ½º´Â ¸®½º´× ¼ÒÄÏÀ» ¼³Á¤ÇÏ°í ±× ¼ÒÄÏÀÌ ¹Þ´Â ¸ðµç µ¥ÀÌÅ͸¦ ¹«½ÃÇÑ´Ù.
ÀÌ ¼­ºñ½º´Â ¼­ºñ½º °ÅºÎ Ãë¾àÁ¡ÀÌ Á¸ÀçÇϱ⠶§¹®¿¡ »ç¿ëÇÏÁö ¾ÊÀ» °ÍÀ» ±Ç°íÇÑ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
UNIX, Linux
ÇØ°áÃ¥ ´ÙÀ½°ú °°Àº ÀýÂ÷¿¡ ÀÇÇØ Discard ¼­ºñ½º¸¦ ÀÛµ¿ÁßÁö½Ã±æ °ÍÀ» ±Ç°íÇÑ´Ù:

UNIX ½Ã½ºÅÛ:

1. /etc/inetd.conf ÆÄÀÏ¿¡ ÀÖ´Â discard ¿£Æ®¸®¸¦ ÁÖ¼®Ã³¸® ÇÑ´Ù.
2. ´ÙÀ½ ¸í·É°ú °°ÀÌÇÏ¿© inetd ÇÁ·Î¼¼½º¿¡°Ô ¼öÁ¤µÈ ³»¿ëÀ» ÀÐ¾î µéÀ̵µ·Ï ÇÑ´Ù:
kill -HUP <inetd process id>

*Solaris 10, Solaris 11ÀÇ °æ¿ì:
svcadm disable svc:/network/discard:dgram
svcadm disable svc:/network/discard:stream

*Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
/etc/xinetd.d/discard-dgram ¹× /etc/xinetd.d/discard-streamÀ» ¿­¾î disable=yes·Î ¼³Á¤ÇÑ ÈÄ xinetd¸¦ Àç½ÃÀÛÇÑ´Ù.

À©µµ¿ì NT/2000 ½Ã½ºÅÛ:

discard ¼­ºñ½º¸¸À» ÀÛµ¿ÁßÁö ½ÃÅ°±æ ¿øÇÑ´Ù¸é:
1. ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ¿ÀÇÂÇÏ¿© À©µµ¿ì NT/2000 ½ÃÀÛ ¸Þ´º·ÎºÎÅÍ '½ÇÇà'À» ¼±ÅÃÇÑ ÈÄ, regedt32 ¸¦ ŸÀÌÇÎÇÏ°í 'È®ÀÎ'À» Ŭ¸¯ÇÑ´Ù.
2. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SimpTcp\Parameters Å°¸¦ ¼±ÅÃÇÑ´Ù.
3. EnableTcpDiscard ¸¦ 0À¸·Î ¼³Á¤ÇÑ´Ù.
4. º¯µ¿»çÇ×À» Àû¿ëÇϱâ À§ÇØ 'Simple TCP/IP service'¸¦ Àç½ÃÀÛ½ÃŲ´Ù.

* Windows XP, 2003, VISTA, 7, 2008, 8, 2012, 10, 2016, 2019
1. ½ÇÇàâ(Win Key + R)¿¡¼­ regedit32¸¦ ½ÇÇàÇÑ´Ù.
2. HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SimpTcp\Parameters Å°¸¦ ¼±ÅÃÇÑ´Ù.
3. EnableTcpDiscard ¸¦ 0À¸·Î ¼³Á¤ÇÑ´Ù.
4. º¯µ¿»çÇ×À» Àû¿ëÇϱâ À§ÇØ 'Simple TCP/IP service'¸¦ Àç½ÃÀÛ½ÃŲ´Ù.
°ü·Ã URL CVE-1999-0636 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)