English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14018
À§Çèµµ 40
Æ÷Æ® 514
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù R-Command
»ó¼¼¼³¸í ÇØ´ç RSH µ¥¸óÀº »ç¿ëÀÚµéÀÌ NULL »ç¿ëÀÚ¸íÀ¸·Î ·Î±×ÀÎÀ» Çã¿ëÇÏ¸ç ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.
In.rshd µ¥¸óÀÇ ±¸ ¹öÀüµéÀº ruserok() ¶óÀ̺귯¸® È£Ãâ¿¡ ÀÖ´Â Ãë¾àÁ¡À¸·Î ÀÎÇØ °ø°ÝÀÚ¿¡°Ô NULL »ç¿ëÀÚ·ÎÀÇ ·Î±×ÀÎÀ» Çã¿ëÇÑ´Ù. °ø°ÝÀÚ´Â ÀûÀýÇÑ ÀÎÁõ¾øÀÌ root ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/112.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ Inetd.conf ÆÄÀÏÀ» ÁÖ¼®Ã³¸®Çϰí inetd ÇÁ·Î¼¼½º¸¦ Àç½ÃÀÛÇÏ¿© Ãë¾àÇÑ ½Ã½ºÅÛ»óÀÇ RSH ¼­ºñ½º¸¦ Áï½Ã ÀÛµ¿ÁßÁö½ÃÄÑ¾ß ÇÑ´Ù.

Enterprise Linux 6.4, CentOS 6.4, Fedora 19ÀÇ °æ¿ì
/etc/xinetd.d/rsh ÆÄÀÏÀ» ¿­¾î disableÀ» yes·Î ¼³Á¤ÇÑ´Ù.

Solaris 10, Solaris 11ÀÇ °æ¿ì rsh ¼­ºñ½º ÁßÁö¸¦ À§Çؼ­´Â ´ÙÀ½°ú °°ÀÌ ½ÇÇàÇÑ´Ù.
#svcadm disable svc:/network/login:rlogin

¸¸¾à RSH ¼³ºñ¸¦ »ç¿ëÇØ¾ß ÇÑ´Ù¸é ÆÐÄ¡Á¤º¸¿¡ ´ëÇØ ÇØ´ç º¥´õ¿¡ ¹®ÀÇÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-1999-0180 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)