| Ãë¾àÁ¡ID |
14019 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
514 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
R-Command |
| »ó¼¼¼³¸í |
ÆÐ½º¿öµå°¡ ¼³Á¤µÇÁö ¾Ê¾Ò°Å³ª ~/.rhosts ÆÄÀÏ, ȤÀº /etc/hosts.equiv ÆÄÀÏÀÇ ¼³Á¤³»¿ë¿¡ ¹®Á¦°¡ ÀÖ¾î rshÀ» ÅëÇØ ÇØ´ç ½Ã½ºÅÛ³»¿¡ ÀÖ´Â ÀÓÀÇÀÇ ¸í·ÉÀÇ ¼öÇàÀÌ °¡´ÉÇÏ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/677.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
1. ºÒÇÊ¿äÇÑ ¼ºñ½º¶ó¸é ¼ºñ½º¸¦ Disable ½ÃŲ´Ù. (/etc/inetd.conf¿¡¼ Comment ó¸®, ±×¸®°í inetd µ¥¸óÀ» Revoke ½ÃÅ´) *Solaris 10, Solaris 11ÀÇ °æ¿ì: # svcadm disable svc:/network/login:rlogin
*Enterprise Linux 6.4, CentOS 6.4, Fedora 19: /etc/xinetd.d/rsh¸¦ ¿¾î disable=yes·Î ¼³Á¤ÇÑ´Ù.
2. ÆÐ½º¿öµå°¡ ¼³Á¤µÇÁö ¾ÊÀº Account¶ó¸é ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÑ´Ù. 3. ~/.rhosts ÆÄÀÏÀ̳ª /etc/hosts.equiv ÆÄÀÏÀÇ ¼³Á¤¿¡¼ '+'°¡ ÀÖÀ¸¸é Á¦°ÅÇϰí rshÀ» ÅëÇØ TrustÇÒ È£½ºÆ®¸íÀ̳ª IP¸¦ Á÷Á¢ µî·ÏÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0651 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|