| Ãë¾àÁ¡ID |
14014 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
513 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
R-Command |
| »ó¼¼¼³¸í |
¸î¸î AIX¿Í LinuxÀÇ Rlogin µ¥¸ó¿¡ ÀÖ´Â Ãë¾àÁ¡Àº °ø°ÝÀÚ°¡ ¿ø°ÝÀ¸·Î ½Ã½ºÅÛ¿¡ ´ëÇÑ Çã°¡µÇÁö ¾ÊÀº root ¾×¼¼½º¸¦ ÇÏ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â Rlogin¿¡ -froot ¿É¼ÇÀ» »ç¿ëÇÏ¿© ´ë»ó ¼¹öÀÇ µ¥¸óÀÌ »ç¿ëÀÚ¸¦ root ½©·Î ¶³¾î¶ß·Á ÁÖµµ·Ï ÇÒ ¼ö ÀÖ´Ù. ÀÌ ¹®Á¦Á¡Àº '/bin/login' ÇÁ·Î±×·¥À¸·Î °Ç³×Áø ÀμöµéÀ» À߸ø ÇØ¼®ÇÔÀ¸·Î½á ¹ß»ý´Âµ¥, ÀÌ´Â °á°úÀûÀ¸·Î °ø°ÝÀÚ°¡ ÆÐ½º¿öµå¸¦ À§ÇÑ ÇÁ·ÒÇÁÆ® ¾øÀÌ °ð¹Ù·Î root »ç¿ëÀÚ·Î ·Î±×ÀÎÇÏ°Ô ÇØ ÁØ´Ù.
* Âü°í »çÀÌÆ®: http://www.securityfocus.com/bid/458 http://www.iss.net/security_center/static/104.php
Ãë¾àÇÑ ½Ã½ºÅÛµé: AIX 3.x Linux kernel 2.1.x |
| ÇØ°áÃ¥ |
IBM AIX 3¿¡ ´ëÇØ¼´Â: CERT ±Ç°í¾È CA-1994-09 (http://www.cert.org/advisories/CA-1994-09.html ) À» ÂüÁ¶ÇÏ¿© APAR IX44254¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù.
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î /etc/inetd.conf ÆÄÀÏ¿¡¼ RloginÀ» Disable½Ã۰í inetd ÇÁ·Î¼¼½º¸¦ Àç°¡µ¿½ÃŲ´Ù. |
| °ü·Ã URL |
CVE-1999-0113 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|