| Ãë¾àÁ¡ID |
14008 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
22 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
Ssh |
| »ó¼¼¼³¸í |
ÇØ´ç SSH ¼¹öÀÇ ¹öÀüÀº AllowedAuthentications ¼³Á¤ ¹«½Ã Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. Secure ShellÀº SSH Communications »ç¿¡ ÀÇÇØ ¹èÆ÷µÇ°í °ü¸®µÇ´Â »ó¿ë SSH ±¸ÇöÀ¸·Î Unix, Linux, ±×¸®°í ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® À©µµ¿ì Ç÷§Æûµé¿¡ žÀçµÉ ¼ö ÀÖ´Ù. 3.0.0 ÀÌ»ó ±×¸®°í 3.1.2 ÀÌÀüÀÇ SSH ¹öÀüµé¿¡´Â ¾î¶² ȯ°æ±¸¼º ¾Æ·¡¿¡¼, ¿ø°ÝÁöÀÇ »ç¿ëÀÚµéÀÌ À¯È¿ÇÑ ÀÎÁõ ¸ÞÄ¿´ÏÁòÀ¸·Î½á ¸í½ÃÀûÀ¸·Î µî·ÏµÇÁö ¾ÊÀº ÀÎÁõ ¸ÞÄ¿´ÏÁòÀÎ ÆÐ½º¿öµå ¹æ½ÄÀÇ ÀÎÁõÀ» Çã¿ëÇÑ´Ù. À̰ÍÀº »ç¿ëÀÚ°¡ ÆÐ½º¿öµå¿Í °°Àº Ãë¾àÇÑ ÀÎÁõ ¼ö´ÜÀ» ÅëÇØ ÀÎÁõ ¹ÞÀ» ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. °·ÂÇÑ ÀÎÁõ ÇÁ·ÎÅäÄÝÀÌ ´ëüµÇ°í ½Ã½ºÅÛ »ç¿ëÀÚ °èÁ¤µéÀÌ Ãë¾àÇÑ ÆÐ½º¿öµåµé·Î º¸È£µÇ°í ÀÖ´Ù¸é °ø°ÝÀÚ´Â °·ÂÇÑ ÀÎÁõ ±â¹ýÀÌ ¾Æ´Ñ Ãë¾àÇÑ ÆÐ½º¿öµå¸¦ ÅëÇØ ½Ã½ºÅÛÀ¸·ÎÀÇ ¾×¼¼½º¸¦ ¾òÀ» ¼ö ÀÖ´Ù. Áï, °ø°ÝÀÚ´Â ÀÌ °áÇÔÀ» ÀÌ¿ëÇÏ¿© »çÀü ÆÄÀϵéÀ» ÀÌ¿ëÇÑ Brute Force °ø°ÝÀ» ½ÃµµÇÒ ¼ö ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
1. Àӽà Á¶Ä¡¹æ¹ýÀº sshd2_config ÆÄÀÏ¿¡¼ "AllowedAuthentications" ´ë½Å¿¡ "RequiredAuthentications" Ű¿öµå¸¦ »ç¿ëÇÏ´Â °ÍÀÌ´Ù: RequiredAuthentications hostbased, publickey
2. ÀÌ ¹®Á¦°¡ ÇØ°áµÈ SSHÀÇ 3.1.2 ÀÌ»óÀÇ ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å ÇØ¾ß ÇÑ´Ù.
SSH Communications Security Upgrade ssh-3.1.2.tar.gz http://www.ssh.com/products/ssh/download.cfm |
| °ü·Ã URL |
CVE-2002-1646 (CVE) |
| °ü·Ã URL |
4810 (SecurityFocus) |
| °ü·Ã URL |
9163 (ISS) |
|