English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14008
À§Çèµµ 20
Æ÷Æ® 22
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù Ssh
»ó¼¼¼³¸í ÇØ´ç SSH ¼­¹öÀÇ ¹öÀüÀº AllowedAuthentications ¼³Á¤ ¹«½Ã Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
Secure ShellÀº SSH Communications »ç¿¡ ÀÇÇØ ¹èÆ÷µÇ°í °ü¸®µÇ´Â »ó¿ë SSH ±¸ÇöÀ¸·Î Unix, Linux, ±×¸®°í ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® À©µµ¿ì Ç÷§Æûµé¿¡ žÀçµÉ ¼ö ÀÖ´Ù. 3.0.0 ÀÌ»ó ±×¸®°í 3.1.2 ÀÌÀüÀÇ SSH ¹öÀüµé¿¡´Â ¾î¶² ȯ°æ±¸¼º ¾Æ·¡¿¡¼­, ¿ø°ÝÁöÀÇ »ç¿ëÀÚµéÀÌ À¯È¿ÇÑ ÀÎÁõ ¸ÞÄ¿´ÏÁòÀ¸·Î½á ¸í½ÃÀûÀ¸·Î µî·ÏµÇÁö ¾ÊÀº ÀÎÁõ ¸ÞÄ¿´ÏÁòÀÎ ÆÐ½º¿öµå ¹æ½ÄÀÇ ÀÎÁõÀ» Çã¿ëÇÑ´Ù. À̰ÍÀº »ç¿ëÀÚ°¡ ÆÐ½º¿öµå¿Í °°Àº Ãë¾àÇÑ ÀÎÁõ ¼ö´ÜÀ» ÅëÇØ ÀÎÁõ ¹ÞÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. °­·ÂÇÑ ÀÎÁõ ÇÁ·ÎÅäÄÝÀÌ ´ëüµÇ°í ½Ã½ºÅÛ »ç¿ëÀÚ °èÁ¤µéÀÌ Ãë¾àÇÑ ÆÐ½º¿öµåµé·Î º¸È£µÇ°í ÀÖ´Ù¸é °ø°ÝÀÚ´Â °­·ÂÇÑ ÀÎÁõ ±â¹ýÀÌ ¾Æ´Ñ Ãë¾àÇÑ ÆÐ½º¿öµå¸¦ ÅëÇØ ½Ã½ºÅÛÀ¸·ÎÀÇ ¾×¼¼½º¸¦ ¾òÀ» ¼ö ÀÖ´Ù. Áï, °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» ÀÌ¿ëÇÏ¿© »çÀü ÆÄÀϵéÀ» ÀÌ¿ëÇÑ Brute Force °ø°ÝÀ» ½ÃµµÇÒ ¼ö ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ 1. Àӽà Á¶Ä¡¹æ¹ýÀº sshd2_config ÆÄÀÏ¿¡¼­ "AllowedAuthentications" ´ë½Å¿¡ "RequiredAuthentications" Ű¿öµå¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù:
RequiredAuthentications
hostbased, publickey

2. ÀÌ ¹®Á¦°¡ ÇØ°áµÈ SSHÀÇ 3.1.2 ÀÌ»óÀÇ ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.

SSH Communications Security Upgrade ssh-3.1.2.tar.gz
http://www.ssh.com/products/ssh/download.cfm
°ü·Ã URL CVE-2002-1646 (CVE)
°ü·Ã URL 4810 (SecurityFocus)
°ü·Ã URL 9163 (ISS)