English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14003
À§Çèµµ 40
Æ÷Æ® 23
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù TELNET
»ó¼¼¼³¸í ÇØ´ç Telnet ¼­¹ö´Â AYT ('Are You There') ¸í·ÉÀÇ ±ä ½ÃÄö½º¸¦ ¹ÞÀ¸¸é ¿¬°áÀÌ ²÷¾îÁø´Ù. À̰ÍÀº ³»ºÎ ¹öÆÛÁßÀÇ Çϳª¿¡ ¿À¹öÇ÷ο찡 ¹ß»ýÇÏ¿© Å©·¡½¬°¡ ³­ °ÍÀ» ÀǹÌÇÑ´Ù. À̰ÍÀº Attacker°¡ ÀÌ ¹ö±×¸¦ ÀÌ¿ëÇÏ¿© ÇØ´ç ¼­¹öÀÇ root ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ´Ù´Â °Í°ú °°´Ù.
ÀÌ Ãë¾àÁ¡Àº BSD telnet µ¥¸ó¿¡¼­ À¯·¡µÈ telnet µ¥¸óµé¿¡ Á¸ÀçÇÑ´Ù. ¾î¶² Á¶°ÇÇÏ¿¡¼­ telnet ÇÁ·ÎÅäÄÝ ¿É¼Çµé, ƯÈ÷ 'AYT' (Are You There) ¿É¼ÇÀÇ Á¶ÇÕÀ» µ¥¸óÀÌ ¹ÞÀ¸¸é ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÑ´Ù. ±× ¿É¼ÇÀ» ó¸®Çϴµ¥ °ü¿©ÇÏ´Â ÇÔ¼ö(function)´Â ¾î¶°ÇÑ ±æÀÌ Ã¼Å· °úÁ¤µµ ¾øÀÌ °íÁ¤µÈ Å©±âÀÇ ¹öÆÛ·Î ÀÀ´ä ÆÐŶÀ» Á¦ÀÛÇÑ´Ù. À̰ÍÀÌ °¡´ÉÇÏ´Ù¸é telnet µ¥¸óÀÇ ±ÇÇÑ, ´ë°³ rootÀÇ ±ÇÇÑÀ¸·Î ¿ø°ÝÁö ½Ã½ºÅÛ »ó¿¡¼­ ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securityfocus.com/bid/3064
http://www.iss.net/security_center/static/6875.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Systems running versions of telnetd derived from BSD source
Apple MacOS X 10.0
BSDI 4.x default
Cisco applications running on a unpatched Sun Solaris OS
OpenBSD 2.x
FreeBSD [2345].x default
NetBSD 1.x default
Hewlett-Packard's HP-UX 10.x
IBM AIX versions 4.3 and earlier and 5.1
IRIX 6.5.x
Sun Solaris 8 and earlier
SCO OpenServer 5.0.6a and earlier
Linux netkit-telnetd < 0.14
ÇØ°áÃ¥ ´ÙÀ½ CERT ±Ç°í¾È CA-2001-21À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ ±¸ÇÏ¿© ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù:
http://www.cert.org/advisories/CA-2001-21.html
°ü·Ã URL CVE-2001-0554 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)